PT-2018-13165 · Zoom · Zoom

Published

2018-11-30

·

Updated

2019-10-09

·

CVE-2018-15715

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom clients on Windows versions prior to 4.1.34814.1119 Zoom clients on Mac OS versions prior to 4.1.34801.1116 Zoom clients on Linux versions 2.4.129780.0915 and below
Description The issue allows a remote unauthenticated attacker to spoof UDP messages from a meeting attendee or Zoom server, invoking functionality in the target client. This enables the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Recommendations For Windows versions prior to 4.1.34814.1119, update to version 4.1.34814.1119 or later. For Mac OS versions prior to 4.1.34801.1116, update to version 4.1.34801.1116 or later. For Linux versions 2.4.129780.0915 and below, update to a version later than 2.4.129780.0915.

Exploit

Fix

RCE

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15715

Affected Products

Zoom