CVE-2020-11500: High severity zoom cloud meetings vulnerability
Published Apr 3, 2020
·Updated
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.
Affected Software
1 affected component
Zoom Meetings<=4.6.9
Event History
Apr 3, 2020
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Zoom security issue?
The vulnerability ID for this Zoom security issue is CVE-2020-11500.
2
What is the severity rating of CVE-2020-11500?
CVE-2020-11500 has a severity rating of 7.5 (high).
3
What is the description of CVE-2020-11500?
CVE-2020-11500 is a vulnerability in Zoom Client for Meetings through version 4.6.9 which uses the ECB mode of AES for video and audio encryption, making it less secure.
4
Which software versions are affected by CVE-2020-11500?
Zoom Meetings version 4.6.9 and below are affected by CVE-2020-11500.
5
How can I fix CVE-2020-11500?
To fix CVE-2020-11500, you should update Zoom Client for Meetings to a version above 4.6.9 that does not use ECB mode for encryption, and enforce strong encryption protocols.