PT-2021-18752 · Zoom · Zoom Chat
Daan Keuper
+1
·
Published
2021-04-09
·
Updated
2021-09-21
·
CVE-2021-30480
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zoom Chat versions through 2021-04-09
Description
The issue allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. This is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
Recommendations
For Zoom Chat versions through 2021-04-09, update to a version released after 2021-04-09 to resolve the issue. As a temporary workaround, consider restricting access to the Zoom Chat software to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoom Chat