Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.
References
Link | Resource |
---|---|
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-19810-Java%20RMI%20Deserialization-ZoomCallRecording | Exploit Third Party Advisory |
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-19810-Java%20RMI%20Deserialization-ZoomCallRecording | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 04:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-19810-Java%20RMI%20Deserialization-ZoomCallRecording - Exploit, Third Party Advisory |
30 Nov 2021, 22:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:eleveo:call_recording:6.3.1:*:*:*:*:*:*:* |
17 Nov 2021, 22:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host. |
03 Nov 2021, 13:59
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-19810-Java%20RMI%20Deserialization-ZoomCallRecording - Exploit, Third Party Advisory | |
References | (MISC) https://support.zoom.us/hc/en-us/articles/201362473-Local-Recording - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 10.0 |
CPE | cpe:2.3:a:zoom:call_recording:6.3.1:*:*:*:*:*:*:* | |
CWE | CWE-502 |
28 Oct 2021, 11:56
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-10-28 11:15
Updated : 2024-11-21 04:35
NVD link : CVE-2019-19810
Mitre link : CVE-2019-19810
CVE.ORG link : CVE-2019-19810
JSON object : View
Products Affected
eleveo
- call_recording
CWE
CWE-502
Deserialization of Untrusted Data