First published: Wed Apr 01 2020(Updated: )
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <=4.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Zoom vulnerability is CVE-2020-11470.
The title of this Zoom vulnerability is 'Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement which…'
This Zoom vulnerability allows a local process to obtain unprompted microphone and camera access on macOS.
An attacker can exploit this Zoom vulnerability by loading a crafted library and inheriting Zoom Client's microphone and camera access.
The severity rating for this Zoom vulnerability is low.