First published: Fri Apr 17 2020(Updated: )
** DISPUTED ** airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | =4.6.11 | |
=4.6.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-11876.
The severity of CVE-2020-11876 is high with a severity value of 7.5.
The affected software for CVE-2020-11876 is Zoom Meetings version 4.6.11 on Windows.
CVE-2020-11876 refers to the use of a disputed SHA-256 hash for initialization of an OpenSSL EVP AES-256 CBC context in airhost.exe in Zoom Client for Meetings 4.6.11.
Please refer to the vendor's website or security advisories for information on available fixes for CVE-2020-11876.