CVE-2019-13449
Summary
| CVE | CVE-2019-13449 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-09 06:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website! | medium.com | ||
| Response to Video-On Concern - Zoom Blog | MISC | blog.zoom.us | Vendor Advisory |
| assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf | MISC | assets.zoom.us | Vendor Advisory |
| 951540 - chromium - An open-source project to help move the web forward. - Monorail | MISC | bugs.chromium.org | Exploit, Third Party Advisory |
| Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website! | MISC | medium.com | Third Party Advisory |
| Zoom على تويتر: "[Update] The July 9 patch to the Zoom app on Mac devices detailed earlier on our blog is now live. Details on the various fixes contained within it are explained, as well as how to update the Zoom software. See blog post here: https://t.co/56yDgoZf1U" | MISC | twitter.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.