Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.
References
Link | Resource |
---|---|
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-19810-Java%20RMI%20Deserialization-ZoomCallRecording | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-10-28 11:15
Updated : 2024-02-28 18:48
NVD link : CVE-2019-19810
Mitre link : CVE-2019-19810
CVE.ORG link : CVE-2019-19810
JSON object : View
Products Affected
eleveo
- call_recording
CWE
CWE-502
Deserialization of Untrusted Data