6.5

CVE-2019-13449

Exploit
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZoomZoom SwPlatformmac_os_x Version < 4.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2% 0.781
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf
Vendor Advisory
https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/
Vendor Advisory
https://bugs.chromium.org/p/chromium/issues/detail?id=951540
Third Party Advisory
Exploit
https://medium.com/%40jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
https://twitter.com/zoom_us/status/1148710712241295361
Third Party Advisory