CVE-2020-11876: High severity zoom client for meetings vulnerability
Published Apr 17, 2020
·Updated
DISPUTED airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code.
Affected Software
1 affected component
Zoom Meetings Windows=4.6.11
Event History
Apr 17, 2020
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
Description
Disputed
04:15 PM
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-11876.
2
What is the severity of CVE-2020-11876?
The severity of CVE-2020-11876 is high with a severity value of 7.5.
3
What is the affected software for CVE-2020-11876?
The affected software for CVE-2020-11876 is Zoom Meetings version 4.6.11 on Windows.
4
What is the description of CVE-2020-11876?
CVE-2020-11876 refers to the use of a disputed SHA-256 hash for initialization of an OpenSSL EVP AES-256 CBC context in airhost.exe in Zoom Client for Meetings 4.6.11.
5
Is there a fix available for CVE-2020-11876?
Please refer to the vendor's website or security advisories for information on available fixes for CVE-2020-11876.