CRITICAL🇵🇱 Wersja polska

CVE-2020-6109

CVSS 9.8v3.1pub. 2020-06-08upd. 2024-11-21

An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Zoom

    APP
    Zoom
    4.6.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2024-24691CRITICAL9.6PL ✓same product

Privilege escalation w Zoom Desktop Client, VDI Client i Meeting SDK dla Windows

CVE-2023-39216CRITICAL9.6PL ✓same product

Nieprawidłowa walidacja danych wejściowych w Zoom Desktop Client dla Windows — privilege escalation

CVE-2023-39213CRITICAL9.6PL ✓same product

Zoom Desktop Client i VDI Client — privilege escalation przez sieć

CVE-2023-36534CRITICAL9.3PL ✓same product

Path traversal w Zoom Desktop Client dla Windows — eskalacja uprawnień

CVE-2022-28755CRITICAL9.6PL ✓same product

Zoom Client — podatność parsowania URL umożliwiająca RCE