CVE-2019-19810: Critical severity eleveo call recording vulnerability
Published Oct 28, 2021
·Updated
Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.
Affected Software
1 affected component
Eleveo Call Recording=6.3.1
Event History
Oct 28, 2021
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19810?
CVE-2019-19810 is classified as critical with a CVSS score of 10.
2
How do I fix CVE-2019-19810?
To mitigate CVE-2019-19810, update Eleveo Call Recording to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2019-19810 involve?
CVE-2019-19810 involves Java Deserialization attacks that target the RMI service.
4
Can CVE-2019-19810 be exploited remotely?
Yes, CVE-2019-19810 can be exploited remotely by an unauthenticated attacker.
5
What are the potential impacts of CVE-2019-19810?
The potential impacts of CVE-2019-19810 include arbitrary code execution on the target host.