peter bassill · operator
$ cve CVE-2019-19810 JSON

CVE-2019-19810

10.0
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS5.1% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2021-10-28
Last modified2026-06-17

Affected (1)

VendorProduct
eleveocall recording

References

→ the Explorer  ·  watch your stack  ·  NVD