First published: Fri Apr 17 2020(Updated: )
** DISPUTED ** airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Client for Meetings | =4.6.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Zoom Client for Meetings vulnerability is CVE-2020-11877.
The severity of CVE-2020-11877 is high with a CVSS score of 7.5.
The affected software for CVE-2020-11877 is Zoom Meetings version 4.6.11 on Windows.
The issue is that airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption.
The vendor states that this IV is used only within unreachable code.