PT-2018-13165 · Zoom · Zoom
Published
2018-11-30
·
Updated
2019-10-09
·
CVE-2018-15715
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoom clients on Windows versions prior to 4.1.34814.1119
Zoom clients on Mac OS versions prior to 4.1.34801.1116
Zoom clients on Linux versions 2.4.129780.0915 and below
Description
The issue allows a remote unauthenticated attacker to spoof UDP messages from a meeting attendee or Zoom server, invoking functionality in the target client. This enables the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Recommendations
For Windows versions prior to 4.1.34814.1119, update to version 4.1.34814.1119 or later.
For Mac OS versions prior to 4.1.34801.1116, update to version 4.1.34801.1116 or later.
For Linux versions 2.4.129780.0915 and below, update to a version later than 2.4.129780.0915.
Exploit
Fix
RCE
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoom