CVE-2018-15715
Last modified
CVE-2018-15715 is a vulnerability of currently unknown severity. Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. EPSS estimates a 3.49% chance of exploitation in the next 30 days.
Description
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Zoom | <= 2.4.129780.0915 |
| Zoom | Zoom | < 4.1.34801.1116 |
| Zoom | Zoom | < 4.1.34814.1119 |
References
- https://www.tenable.com/security/research/tra-2018-40Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2018-40Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15715?
How severe is CVE-2018-15715?
How do I fix CVE-2018-15715?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1571IBM QRadar 7.2 and 7.3 could allow a remote authenticated at…8.8
- CVE-2018-15710Nagios XI 5.5.6 allows local authenticated attackers to esca…
- CVE-2018-15711Nagios XI 5.5.6 allows remote authenticated attackers to res…
- CVE-2018-15712Nagios XI 5.5.6 allows reflected cross site scripting from r…
- CVE-2018-15713Nagios XI 5.5.6 allows persistent cross site scripting from …
- CVE-2018-15714Nagios XI 5.5.6 allows reflected cross site scripting from r…
- CVE-2018-15716NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated r…
- CVE-2018-15717Open Dental before version 18.4 stores user passwords as bas…
- CVE-2018-15718Open Dental before version 18.4 transmits the entire user da…
- CVE-2018-15719Open Dental before version 18.4 installs a mysql database an…
- CVE-2018-15720Logitech Harmony Hub before version 4.15.206 contained two h…
- CVE-2018-15721The XMPP server in Logitech Harmony Hub before version 4.15.…
Are you affected by CVE-2018-15715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
