Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Zoom: CVE-2018-15715: Zoom Message Spoofing

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Nov 30, 2018
Added
Dec 27, 2018
Modified
Apr 24, 2019

Description

A flaw in Zoom's thick client allows attackers to hijack control of presenters’ desktops, spoof chat messages, and kick attendees out of Zoom calls. The flaw is due to the lack of message validation. An attacker can spoof Zoom server messages to invoke restricted functionalities reserved for Zoom servers.

Solutions

zoom-windows-upgrade-4_1_34460_1105zoom-mac-upgrade-4_1_34475_1105zoom-linux-upgrade-2_5_146186_1130zoom-chrome-upgrade-3_3_1635_1130
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.