{"api_version":"1","generated_at":"2026-07-23T12:30:22+00:00","cve":"CVE-2019-13450","urls":{"html":"https://cve.report/CVE-2019-13450","api":"https://cve.report/api/cve/CVE-2019-13450.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-13450","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-13450"},"summary":{"title":"CVE-2019-13450","description":"In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-07-09 06:15:00","updated_at":"2023-11-07 03:03:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://medium.com/%40jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5","name":"https://medium.com/%40jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5","refsource":"","tags":[],"title":"Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/","name":"https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Response to Video-On Concern - Zoom Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/109082","name":"109082","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Zoom Client CVE-2019-13450 Remote Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://news.ycombinator.com/item?id=20387298","name":"https://news.ycombinator.com/item?id=20387298","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"Vulnerability in the Mac Zoom client allows malicious websites to enable camera | Hacker News","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf","name":"https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf","refsource":"MISC","tags":["Vendor Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.chromium.org/p/chromium/issues/detail?id=951540","name":"https://bugs.chromium.org/p/chromium/issues/detail?id=951540","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"951540 - \n \n \n chromium -\n \n \n An open-source project to help move the web forward. - \n \n Monorail","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5","name":"https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5","refsource":"MISC","tags":["Third Party Advisory"],"title":"Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/moreati/status/1148548799813640193","name":"https://twitter.com/moreati/status/1148548799813640193","refsource":"MISC","tags":["Third Party Advisory"],"title":"Alex Willmer on Twitter: \"From what I can tell https://t.co/bZ5vlJDcr7 (joining video calls without user interaction) affects Zoom on Windows and Linux, as well as macOS. That's not clear from the Medium post, or HN discussion\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/zoom_us/status/1148710712241295361","name":"https://twitter.com/zoom_us/status/1148710712241295361","refsource":"MISC","tags":["Third Party Advisory"],"title":"Zoom على تويتر: \"[Update] The July 9 patch to the Zoom app on Mac devices detailed earlier on our blog is now live. Details on the various fixes contained within it are explained, as well as how to update the Zoom software. See blog post here: https://t.co/56yDgoZf1U\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-13450","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13450","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"13450","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ringcentral","cpe5":"ringcentral","cpe6":"7.0.136380.0312","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"mac_os_x","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13450","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ringcentral","cpe5":"ringcentral","cpe6":"7.0.136380.0312","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"mac_os_x","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"13450","vulnerable":"1","versionEndIncluding":"4.4.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"zoom","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"mac_os_x","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-13450","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5","refsource":"MISC","name":"https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5"},{"url":"https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf","refsource":"MISC","name":"https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf"},{"url":"https://news.ycombinator.com/item?id=20387298","refsource":"MISC","name":"https://news.ycombinator.com/item?id=20387298"},{"refsource":"MISC","name":"https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/","url":"https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/"},{"refsource":"MISC","name":"https://twitter.com/moreati/status/1148548799813640193","url":"https://twitter.com/moreati/status/1148548799813640193"},{"refsource":"BID","name":"109082","url":"http://www.securityfocus.com/bid/109082"},{"refsource":"MISC","name":"https://twitter.com/zoom_us/status/1148710712241295361","url":"https://twitter.com/zoom_us/status/1148710712241295361"},{"refsource":"MISC","name":"https://bugs.chromium.org/p/chromium/issues/detail?id=951540","url":"https://bugs.chromium.org/p/chromium/issues/detail?id=951540"}]}},"nvd":{"publishedDate":"2019-07-09 06:15:00","lastModifiedDate":"2023-11-07 03:03:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ringcentral:ringcentral:7.0.136380.0312:*:*:*:*:mac_os_x:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:zoom:*:*:*:*:*:mac_os_x:*:*","versionEndIncluding":"4.4.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"13450","Ordinal":"151809","Title":"CVE-2019-13450","CVE":"CVE-2019-13450","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"13450","Ordinal":"1","NoteData":"In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"13450","Ordinal":"2","NoteData":"2019-07-09","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"13450","Ordinal":"3","NoteData":"2019-07-12","Type":"Other","Title":"Modified"}]}}}