CVE-2021-30480
Status: ModifiedHigh (8.8)—
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 5.84%
- Percentile among all scored CVEs: 93
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-noinfo
References
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/
- https://explore.zoom.us/en/trust/security/security-bulletin/
- https://sector7.computest.nl/post/2021-08-zoom/
- https://twitter.com/thezdi/status/1379855435730149378
- https://twitter.com/thezdi/status/1379859851061395459
- https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2own
- https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/
- https://www.zerodayinitiative.com/advisories/ZDI-21-971/
- https://zoom.us/feature/messaging
- https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/
- https://explore.zoom.us/en/trust/security/security-bulletin/
- https://sector7.computest.nl/post/2021-08-zoom/
- https://twitter.com/thezdi/status/1379855435730149378
- https://twitter.com/thezdi/status/1379859851061395459
- https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2own
- https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/
- https://www.zerodayinitiative.com/advisories/ZDI-21-971/
- https://zoom.us/feature/messaging
Raw JSON (NVD)
Show
{
"id": "CVE-2021-30480",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-04-09T23:15:12.957",
"references": [
{
"url": "https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://sector7.computest.nl/post/2021-08-zoom/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://twitter.com/thezdi/status/1379855435730149378",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://twitter.com/thezdi/status/1379859851061395459",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2own",
"tags": [
"Press/Media Coverage",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/",
"tags": [
"Press/Media Coverage",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-971/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://zoom.us/feature/messaging",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sector7.computest.nl/post/2021-08-zoom/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://twitter.com/thezdi/status/1379855435730149378",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://twitter.com/thezdi/status/1379859851061395459",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.securityweek.com/200000-awarded-zero-click-zoom-exploit-pwn2own",
"tags": [
"Press/Media Coverage",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/",
"tags": [
"Press/Media Coverage",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-971/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://zoom.us/feature/messaging",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software."
},
{
"lang": "es",
"value": "Zoom Chat versión hasta el 09-04-2021 en Windows y macOS, permite a determinados atacantes autenticados remotamente ejecutar código arbitrario sin la interacción del usuario. Un atacante debe pertenecer a la misma organización o una parte externa que haya sido aceptada como contacto. NOTA: esto es específico del software Zoom Chat, que es diferente de la funcionalidad de chat del software Zoom Meetings y Zoom Video Webinars"
}
],
"lastModified": "2026-06-17T03:50:19.193",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zoom:chat:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "319ECBD3-CE8D-461B-A0C8-B1586E8F9B29",
"versionEndIncluding": "2021-04-09"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "387021A0-AF36-463C-A605-32EA7DAC172E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}