PT-2021-18752 · Zoom · Zoom Chat

Daan Keuper

+1

·

Published

2021-04-09

·

Updated

2021-09-21

·

CVE-2021-30480

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoom Chat versions through 2021-04-09
Description The issue allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. This is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
Recommendations For Zoom Chat versions through 2021-04-09, update to a version released after 2021-04-09 to resolve the issue. As a temporary workaround, consider restricting access to the Zoom Chat software to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-30480

Affected Products

Zoom Chat