Vulnerability Description
airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Meetings | 4.6.11 |
Related Weaknesses (CWE)
References
- https://dev.io/posts/zoomzoo/ExploitThird Party Advisory
- https://dev.io/posts/zoomzoo/ExploitThird Party Advisory
FAQ
What is CVE-2020-11876?
CVE-2020-11876 is a vulnerability with a CVSS score of 7.5 (HIGH). airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initializat...
How severe is CVE-2020-11876?
CVE-2020-11876 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11876?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meetings.