6.5
CVE-2019-13449
- EPSS 2%
- Veröffentlicht 09.07.2019 06:15:10
- Zuletzt bearbeitet 21.11.2024 04:24:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2% | 0.781 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf
https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/
https://bugs.chromium.org/p/chromium/issues/detail?id=951540
https://medium.com/%40jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
https://twitter.com/zoom_us/status/1148710712241295361