PT-2020-3655 · Zoom · Zoom Client+1

Published

2020-06-08

·

Updated

2022-05-12

·

CVE-2020-6110

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Client version 4.6.10
Description An exploitable partial path traversal issue exists in the way Zoom Client processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this issue. For the most severe effect, target user interaction is required.
Recommendations For Zoom Client version 4.6.10, consider disabling the shared code snippets feature until a patch is available. Restrict access to chat messages that include shared code snippets to minimize the risk of exploitation. Avoid using shared code snippets in chat messages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04003
CVE-2020-6110

Affected Products

Zoom Client
Zoom