Vulnerability Description
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Meetings | <= 4.6.8 |
Related Weaknesses (CWE)
References
- https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/Vendor Advisory
- https://objective-see.com/blog/blog_0x56.htmlExploitThird Party Advisory
- https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/Vendor Advisory
- https://objective-see.com/blog/blog_0x56.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-11470?
CVE-2020-11470 is a vulnerability with a CVSS score of 3.3 (LOW). Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera acc...
How severe is CVE-2020-11470?
CVE-2020-11470 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11470?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meetings.