CVE-2020-11877: High severity zoom client for meetings vulnerability
Published Apr 17, 2020
·Updated
DISPUTED airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code.
Affected Software
1 affected component
Zoom Meetings Windows=4.6.11
Event History
Apr 17, 2020
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
Description
Disputed
04:15 PM
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Zoom Client for Meetings vulnerability?
The vulnerability ID of this Zoom Client for Meetings vulnerability is CVE-2020-11877.
2
What is the severity of CVE-2020-11877?
The severity of CVE-2020-11877 is high with a CVSS score of 7.5.
3
What is the affected software for CVE-2020-11877?
The affected software for CVE-2020-11877 is Zoom Meetings version 4.6.11 on Windows.
4
What is the issue with the Initialization Vector (IV) used in airhost.exe for AES-256 CBC encryption in Zoom Client for Meetings 4.6.11?
The issue is that airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption.
5
What does the vendor say about the usage of the IV in airhost.exe for AES-256 CBC encryption in Zoom Client for Meetings 4.6.11?
The vendor states that this IV is used only within unreachable code.