T
Threats
Vivi Windows App 3.12.0 Firewall Vulnerability
Vivi has released Windows App version 3.12.1 to address a firewall vulnerability affecting version 3.12.0 on Intel and AMD Windows devices. Secure-ISS recommends upgrading affected devices as soon as possible.
What happened?
Vivi has identified an issue in the installer for version 3.12.0 of its Windows Client App. The installer creates a Windows Firewall rule that is not correctly scoped to the Vivi Client process, potentially exposing a broader network path than intended.
A Secure-ISS school reported the issue through the Vivi Admin Console. Vivi has since released version 3.12.1 to correct the firewall rule.
Who is affected?
The issue affects:
Vivi Windows Client App version 3.12.0
Intel-based Windows devices
AMD-based Windows devices
The following are not affected:
Windows on ARM devices
macOS, Android, Linux and ChromeOS clients
Vivi Box firmware
Receiver App
Display App
Vivi Windows Client App version 3.10.5 and earlier
Recommended action
Organisations using Vivi Windows Client App version 3.12.0 on affected Windows devices should:
Upgrade to version 3.12.1 as soon as possible.
Confirm the updated client has been deployed across all affected devices.
If version 3.12.1 cannot be deployed, downgrade to version 3.10.5 or earlier until the update is available.
Current risk information
CVE: Not published
CVSS score: Not published
Exploitation status: No active exploitation has been confirmed in the vendor FAQ
Secure-ISS recommends applying the fixed version promptly as a precaution, even though active exploitation has not been confirmed.
Reference
Need Help?
Secure ISS can assist your organisation with assessing exposure, validating ServiceNow instance versions, and planning urgent remediation. Contact the Secure ISS team on 1300 769 460.

