SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-30480

Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction.

HIGH 8.8EPSS 5.84%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
5.84% probability · 93th percentile
CISA KEV
Not listed
Affected
zoom/chat
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.