CVE-2021-30480
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.84%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.84% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- zoom/chat
- Source
- cve@mitre.org
References
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/Third Party Advisory
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
- https://sector7.computest.nl/post/2021-08-zoom/Exploit, Third Party Advisory
- https://twitter.com/thezdi/status/1379855435730149378Third Party Advisory
- https://twitter.com/thezdi/status/1379859851061395459Third Party Advisory
- https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2ownPress/Media Coverage, Third Party Advisory
- https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/Press/Media Coverage, Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-971/Third Party Advisory, VDB Entry
- https://zoom.us/feature/messagingProduct, Vendor Advisory
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/Third Party Advisory
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
- https://sector7.computest.nl/post/2021-08-zoom/Exploit, Third Party Advisory
- https://twitter.com/thezdi/status/1379855435730149378Third Party Advisory
- https://twitter.com/thezdi/status/1379859851061395459Third Party Advisory
- https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2ownPress/Media Coverage, Third Party Advisory
- https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/Press/Media Coverage, Third Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-971/Third Party Advisory, VDB Entry
- https://zoom.us/feature/messagingProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.