3CX DesktopApp security issue
NCSC advice following a security issue in the 3CX DesktopApp.

What has happened?
You may have seen reports that threat actors are actively exploiting a severe security issue in the 3CX DesktopApp.
Affected versions are:
- 18.12.407 and 18.12.416 for Windows platforms
- 18.11.1213, 18.12.402, 18.12.407 and 18.12.416 for macOS
This correlates to Update 7 for Windows, and Updates 6 and 7 for macOS.
Actions to take
The vendor 3CX has published a security alert which advises customers running affected versions to uninstall the software and use the browser-based web app (PWA) until a new version is available. Full instructions are provided.
The NCSC strongly advises all organisations running this software to consult the vendor advisory and take the recommended actions in it.
You may also want to read the following alerts from our international partners:
- Supply Chain attack against 3CXDesktopApp | Cybersecurity & Infrastructure Security Agency
- Supply chain compromise impacting 3CXDesktopApp | Canadian Centre for Cyber Security
- Supply chain compromise of 3CXDesktopApp | Australian Cyber Security Centre
- Supply chain attack against 3CXDesktopApp | CertNZ
Detecting suspicious activity
Indicators of compromise (IoCs) which may help detect related activity are also available:
For general advice on technical approaches to uncovering and remediating malicious activity, see this joint international advisory from CISA, the NCSC and other partners.
Report a compromise
UK organisations affected by this activity should report it.