Rapid7 Vulnerability & Exploit Database

Zoom: CVE-2018-15715: Zoom Message Spoofing

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Zoom: CVE-2018-15715: Zoom Message Spoofing

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
11/30/2018
Created
04/24/2019
Added
12/27/2018
Modified
04/24/2019

Description

A flaw in Zoom's thick client allows attackers to hijack control of presenters’ desktops, spoof chat messages, and kick attendees out of Zoom calls. The flaw is due to the lack of message validation. An attacker can spoof Zoom server messages to invoke restricted functionalities reserved for Zoom servers.

Solution(s)

  • zoom-windows-upgrade-4_1_34460_1105
  • zoom-mac-upgrade-4_1_34475_1105
  • zoom-linux-upgrade-2_5_146186_1130
  • zoom-chrome-upgrade-3_3_1635_1130

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;