CVE-2019-19810

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
28/10/2021
Last modified:
30/11/2021

Description

Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eleveo:call_recording:6.3.1:*:*:*:*:*:*:*