CVE-2018-15715

Description

Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.4

Associated Vulnerability

VulnerabilityOS Platform
Zoom clients on Windows (before version 4.1.34814.1119) are vulnerable to unauthorized message processing.Windows
Vulnerabilities CVE-2018-15715 are affected in Zoom (x64) 4.1.34814.1118Windows
Vulnerabilities CVE-2018-15715 are affected in Zoom 4.1.34814.1118Windows
Vulnerabilities CVE-2018-15715 are affected in Zoom for MAC (Apple Silicon) 2.4.129780.0915Mac
Vulnerabilities CVE-2018-15715 are affected in Zoom for MAC (Apple Silicon) 4.1.34475.1105Mac
Vulnerabilities CVE-2018-15715 are affected in Zoom for MAC (Apple Silicon) 4.1.34583.1107Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-308649Zoom (4.1.35374.1217)
PATCH-611910Zoom IT for MAC (Apple Silicon) (6.5.12.63499)
PATCH-611910Zoom IT for MAC (Apple Silicon) (6.5.12.63499)
PATCH-611910Zoom IT for MAC (Apple Silicon) (6.5.12.63499)
PATCH-352816Zoom Workplace (x64) (6.6.6.19875)
PATCH-352813Zoom Workplace (6.6.6.19875)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234