CVE-2020-6110
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.
- Affected products
- Zoom Client, Zoom
- Zoom
- = 4.6.10
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 4.3% (90th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2020-06-08
CVE-2020-6110 at NVD
No indexed exploits for CVE-2020-6110 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-6110 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.