Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.
References
Link | Resource |
---|---|
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-19810-Java%20RMI%20Deserialization-ZoomCallRecording | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-10-28 04:15
Updated : 2021-11-30 14:09
NVD link : CVE-2019-19810
Mitre link : CVE-2019-19810
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
eleveo
- call_recording