peter bassill · operator
$ cve CVE-2020-6109 JSON

CVE-2020-6109

9.8
CRITICAL · CVSS 3.1 · EPSS 4.7% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.72% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2020-06-08
Last modified2026-06-17

Affected (1)

VendorProduct
zoomzoom

References

→ the Explorer  ·  watch your stack  ·  NVD