High severity8.8NVD Advisory· Published Apr 14, 2020· Updated Jun 17, 2026
CVE-2019-18822
CVE-2019-18822
Description
A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by default, the callrec account) to elevate privileges to root by abusing the callrec-rs@.service. The callrec-rs@.service starts the /opt/callrec/bin/rs binary with root privileges, and this binary is owned by callrec. It can be replaced by a Trojan horse.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ZOOM/Call Recordingdescription
- Range: =6.3.1
Patches
Vulnerability mechanics
References
2- github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-18822-PrivEscal-ZoomCallRecordingnvdExploitThird Party Advisory
- www.zoomint.com/solutions/call-recordingnvdProduct
News mentions
0No linked articles in our index yet.