Vulnerabilities
Vulnerable Software
Zoom:  >> Zoom  Security Vulnerabilities
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
CVSS Score
9.8
EPSS Score
0.013
Published
2018-11-30
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
CVSS Score
8.8
EPSS Score
0.214
Published
2017-12-19
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
CVSS Score
8.8
EPSS Score
0.289
Published
2017-12-19


Contact Us

Shodan ® - All rights reserved