CVE-2020-6110
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
08/06/2020
Last modified:
12/05/2022
Description
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zoom:zoom:4.6.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



