CVE-2019-19810
10.0
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)
In your normal cycle
Critical by CVSS (10), but no sign of active exploitation.
Description
Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 5.1% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-10-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| eleveo | call recording |
References
→ the Explorer · watch your stack · NVD