CVE-2019-18822: Critical severity eleveo call recording vulnerability
A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by default, the callrec account) to elevate privileges to root by abusing the callrec-rs@.service. The callrec-rs@.service starts the /opt/callrec/bin/rs binary with root privileges, and this binary is owned by callrec. It can be replaced by a Trojan horse.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18822?
CVE-2019-18822 is considered critical with a severity score of 9 on the CVSS scale.
How do I fix CVE-2019-18822?
To fix CVE-2019-18822, it is recommended to update to the latest version of Eleveo Call Recording that addresses this privilege escalation issue.
What systems are affected by CVE-2019-18822?
CVE-2019-18822 affects the Eleveo Call Recording software, specifically version 6.3.1.
What type of vulnerability is CVE-2019-18822?
CVE-2019-18822 is a privilege escalation vulnerability that allows users to gain root privileges.
Is CVE-2019-18822 actively being exploited?
There have been reports indicating the potential for exploitation of CVE-2019-18822, highlighting its critical nature.