CVE-2020-11469: High severity zoom meetings vulnerability
Published Apr 1, 2020
·Updated
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.
Affected Software
1 affected component
Zoom Meetings Mac Os<=4.6.8
Event History
Apr 1, 2020
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this Zoom vulnerability?
The vulnerability ID for this Zoom vulnerability is CVE-2020-11469.
2
What is the severity of CVE-2020-11469?
The severity of CVE-2020-11469 is high with a CVSS score of 7.8.
3
How does CVE-2020-11469 affect Zoom?
CVE-2020-11469 affects Zoom Client for Meetings through version 4.6.8 on macOS.
4
What is the impact of CVE-2020-11469?
The impact of CVE-2020-11469 is that a local process with the user's privileges can obtain root access by replacing runwithroot.
5
How can I fix CVE-2020-11469?
To fix CVE-2020-11469, users should update their Zoom Client for Meetings to a version higher than 4.6.8.