8.8
CVSSv3

CVE-2017-15049

Published: 19/12/2017 Updated: 14/05/2021
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The ZoomLauncher binary in the Zoom client for Linux prior to 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote malicious users to execute arbitrary code by leveraging the zoommtg:// scheme handler.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zoom zoom

Exploits

[CONVISO-17-003] - Zoom Linux Client Command Injection Vulnerability (RCE) 1 Advisory Information Conviso Advisory ID: CONVISO-17-003 CVE ID: CVE-2017-15049 CVSS v2: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) Date: 2017-10-01 2 Affected Components Zoom client for Linux, version 201066000904 (zoom_amd64deb) Other versions may be ...
The binary /opt/zoom/ZoomLauncher is vulnerable to command injection because it uses user input to construct a shell command without proper sanitization The client registers a scheme handler (zoommtg://) and this makes possible to trigger the vulnerability remotely Version 201066000904 is affected ...