Java Deserialization Vulnerability in Zoom Call Recording by Eleveo
CVE-2019-19810
10CRITICAL
What is CVE-2019-19810?
The Zoom Call Recording application version 6.3.1 developed by Eleveo is susceptible to Java Deserialization vulnerabilities linked to its built-in RMI service. Remote unauthenticated attackers can leverage this flaw by sending carefully crafted RMI requests, enabling them to execute arbitrary code on the affected system. This vulnerability signifies a serious risk, allowing unauthorized access and control over impacted installations.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
