CVE-2021-30480
Summary
| CVE | CVE-2021-30480 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-09 23:15:00 UTC |
| Updated | 2021-09-21 17:46:00 UTC |
| Description | Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Group Messaging - Zoom | MISC | zoom.us | |
| $200,000 Awarded for Zero-Click Zoom Exploit at Pwn2Own | SecurityWeek.Com | MISC | www.securityweek.com | |
| Zoom zero-day discovery makes calls safer, hackers $200,000 richer - Malwarebytes Labs | Malwarebytes Labs | MISC | blog.malwarebytes.com | |
| JavaScript is not available. | MISC | twitter.com | |
| Zoom RCE from Pwn2Own 2021 · Sector 7 | MISC | sector7.computest.nl | |
| Security Bulletins | Zoom | MISC | explore.zoom.us | |
| Zero Day Initiative on Twitter: "We're still confirming the details of the #Zoom exploit with Daan and Thijs, but here's a better gif of the bug in action. #Pwn2Own #PopCalc… https://t.co/eflVpo5Eh9" | MISC | twitter.com | |
| Critical Zoom vulnerability triggers remote code execution without user input | ZDNet | MISC | www.zdnet.com | |
| ZDI-21-971 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377688 Zoom Client for Meetings Heap Overflow Vulnerability (ZSB-21002)