Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2018-15715

CVE-2018-15715, critical severity (CVSS 9.8): 1 tracked app concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
9.8

NVD scale

Exploitation
3.5 %

EPSS, predicted over 30 days

Tracked apps
1
Still exposed
0

Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS 3.49% above median percentile 88.7%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Zoom macOS us.zoom.xos
    Affected <4.1.34801.1116 Fixed in 4.1.34801.1116 Latest tracked 7.2.1.88329 patched
Vulnerable CPE configurations (2)
Vendor Product Versions
zoom zoom
macOS
<4.1.34801.1116
zoom zoom
Windows
<4.1.34814.1119
View on NVD ↗

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM