CVE-2019-13450
Summary
| CVE | CVE-2019-13450 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-09 06:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ringcentral | Ringcentral | 7.0.136380.0312 | All | All | All |
| Application | Ringcentral | Ringcentral | 7.0.136380.0312 | All | All | All |
| Application | Zoom | Zoom | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website! | medium.com | ||
| Response to Video-On Concern - Zoom Blog | MISC | blog.zoom.us | Vendor Advisory |
| Zoom Client CVE-2019-13450 Remote Security Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Vulnerability in the Mac Zoom client allows malicious websites to enable camera | Hacker News | MISC | news.ycombinator.com | Issue Tracking, Third Party Advisory |
| assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf | MISC | assets.zoom.us | Vendor Advisory |
| 951540 - chromium - An open-source project to help move the web forward. - Monorail | MISC | bugs.chromium.org | Exploit, Third Party Advisory |
| Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website! | MISC | medium.com | Third Party Advisory |
| Alex Willmer on Twitter: "From what I can tell https://t.co/bZ5vlJDcr7 (joining video calls without user interaction) affects Zoom on Windows and Linux, as well as macOS. That's not clear from the Medium post, or HN discussion" | MISC | twitter.com | Third Party Advisory |
| Zoom على تويتر: "[Update] The July 9 patch to the Zoom app on Mac devices detailed earlier on our blog is now live. Details on the various fixes contained within it are explained, as well as how to update the Zoom software. See blog post here: https://t.co/56yDgoZf1U" | MISC | twitter.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.