CVE-2021-34408
- EPSS 0.13%
- Published 27.09.2021 14:15:08
- Last modified 21.11.2024 06:10:20
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a...
- EPSS 3.25%
- Published 27.09.2021 14:15:08
- Last modified 21.11.2024 06:09:45
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated priv...
CVE-2020-11877
- EPSS 0.21%
- Published 17.04.2020 16:15:14
- Last modified 21.11.2024 04:58:48
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code
CVE-2020-11876
- EPSS 0.17%
- Published 17.04.2020 16:15:13
- Last modified 21.11.2024 04:58:48
airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code
CVE-2020-11500
- EPSS 0.44%
- Published 03.04.2020 13:15:13
- Last modified 21.11.2024 04:58:01
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.
CVE-2020-11469
- EPSS 0.14%
- Published 01.04.2020 22:15:17
- Last modified 21.11.2024 04:57:58
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
CVE-2020-11470
- EPSS 0.07%
- Published 01.04.2020 22:15:17
- Last modified 21.11.2024 04:57:58
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inher...