CVE-2021-30480: Critical severity zoom chat vulnerability
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30480?
CVE-2021-30480 has a high severity level due to the potential for remote code execution without user interaction.
How do I fix CVE-2021-30480?
To mitigate CVE-2021-30480, ensure you update Zoom Chat to a version released after April 9, 2021.
Who is affected by CVE-2021-30480?
CVE-2021-30480 affects users of Zoom Chat up to the version released on April 9, 2021, on Windows and macOS.
What type of attack does CVE-2021-30480 enable?
CVE-2021-30480 enables remote authenticated attackers to execute arbitrary code within the affected Zoom Chat application.
Is CVE-2021-30480 a user-interaction vulnerability?
No, CVE-2021-30480 does not require user interaction for exploitation, making it particularly dangerous.