PT-2018-13165 · Zoom · Zoom
Publicado
2018-11-30
·
Atualizado
2019-10-09
·
CVE-2018-15715
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoom clients on Windows versions prior to 4.1.34814.1119
Zoom clients on Mac OS versions prior to 4.1.34801.1116
Zoom clients on Linux versions 2.4.129780.0915 and below
Description
The issue allows a remote unauthenticated attacker to spoof UDP messages from a meeting attendee or Zoom server, invoking functionality in the target client. This enables the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Recommendations
For Windows versions prior to 4.1.34814.1119, update to version 4.1.34814.1119 or later.
For Mac OS versions prior to 4.1.34801.1116, update to version 4.1.34801.1116 or later.
For Linux versions 2.4.129780.0915 and below, update to a version later than 2.4.129780.0915.
Exploit
Correção
RCE
Authentication Bypass by Spoofing
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zoom