Skip to main content
HIGH

CVE-2019-13567

CVSS v3

8.8

HIGH

EPSS Score

1.5 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.

Technical details

Published
2019-07-12

Frequently asked questions

What is CVE-2019-13567?

The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.

Is CVE-2019-13567 actively exploited?

Active exploitation of CVE-2019-13567 has not been confirmed. The EPSS score is 1.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-13567?

CVE-2019-13567 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-13567 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key