PT-2018-13165 · Zoom · Zoom

Publicado

2018-11-30

·

Atualizado

2019-10-09

·

CVE-2018-15715

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom clients on Windows versions prior to 4.1.34814.1119 Zoom clients on Mac OS versions prior to 4.1.34801.1116 Zoom clients on Linux versions 2.4.129780.0915 and below
Description The issue allows a remote unauthenticated attacker to spoof UDP messages from a meeting attendee or Zoom server, invoking functionality in the target client. This enables the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Recommendations For Windows versions prior to 4.1.34814.1119, update to version 4.1.34814.1119 or later. For Mac OS versions prior to 4.1.34801.1116, update to version 4.1.34801.1116 or later. For Linux versions 2.4.129780.0915 and below, update to a version later than 2.4.129780.0915.

Exploit

Correção

RCE

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-15715

Produtos afetados

Zoom