CVE-2018-15715
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.
Los clientes de Zoom en Windows (antes de la versión 4.1.34814.1119), Mac OS (antes de la versión 4.1.34801.1116) y Linux (2.4.129780.0915 y anteriores) son vulnerables al procesamiento no autorizado de imágenes. Un atacante remoto no autenticado puede suplantar los mensajes UDP de un asistente a la reunión o de un servidor de Zoom para invocar funcionalidades en el cliente objetivo. Esto permite que el atacante elimine asistentes de las reuniones, suplante mensajes de los usuarios o secuestre pantallas compartidas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-22 CVE Reserved
- 2018-11-30 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.tenable.com/security/research/tra-2018-40 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zoom Search vendor "Zoom" | Zoom Search vendor "Zoom" for product "Zoom" | <= 2.4.129780.0915 Search vendor "Zoom" for product "Zoom" and version " <= 2.4.129780.0915" | linux |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom Search vendor "Zoom" for product "Zoom" | < 4.1.34801.1116 Search vendor "Zoom" for product "Zoom" and version " < 4.1.34801.1116" | mac_os_x |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom Search vendor "Zoom" for product "Zoom" | < 4.1.34814.1119 Search vendor "Zoom" for product "Zoom" and version " < 4.1.34814.1119" | windows |
Affected
|