Zoom Chat through 2021-04-09 on Windows and macOS allows certain...
Vulnerability Description
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-30480
Credits & Attribution
No credits recorded in the NVD database.
References
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/
- https://twitter.com/thezdi/status/1379855435730149378
- https://twitter.com/thezdi/status/1379859851061395459
- https://zoom.us/feature/messaging
- https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2own
- https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/
- https://www.zerodayinitiative.com/advisories/ZDI-21-971/
- https://explore.zoom.us/en/trust/security/security-bulletin/
- https://sector7.computest.nl/post/2021-08-zoom/
More from zoom
View All →Affected Vendor
zoom
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.