CVE-2018-15715
Last modified
CVE-2018-15715 is a vulnerability of currently unknown severity. Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. EPSS estimates a 3.49% chance of exploitation in the next 30 days.
Description
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Zoom | <= 2.4.129780.0915 |
| Zoom | Zoom | < 4.1.34801.1116 |
| Zoom | Zoom | < 4.1.34814.1119 |
References
- https://www.tenable.com/security/research/tra-2018-40Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2018-40Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15715?
How severe is CVE-2018-15715?
How do I fix CVE-2018-15715?
Are you affected by CVE-2018-15715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
