zoom CVE Vulnerabilities & Metrics

Focus on zoom vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About zoom Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with zoom. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total zoom CVEs: 148
Earliest CVE date: 06 Aug 2004, 04:00 UTC
Latest CVE date: 25 Feb 2025, 20:15 UTC

Latest CVE reference: CVE-2024-45426

Rolling Stats

30-day Count (Rolling): 3
365-day Count (Rolling): 18

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -72.31%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -72.31%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical zoom CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.8

Max CVSS: 10.0

Critical CVEs (≥9): 5

CVSS Range vs. Count

Range Count
0.0-3.9 108
4.0-6.9 27
7.0-8.9 10
9.0-10.0 5

CVSS Distribution Chart

Top 5 Highest CVSS zoom CVEs

These are the five CVEs with the highest CVSS scores for zoom, sorted by severity first and recency.

All CVEs for zoom

CVE-2024-45426 zoom vulnerability CVSS: 0 25 Feb 2025, 20:15 UTC

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

CVE-2024-45418 zoom vulnerability CVSS: 0 25 Feb 2025, 20:15 UTC

Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.

CVE-2024-45417 zoom vulnerability CVSS: 0 25 Feb 2025, 20:15 UTC

Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.

CVE-2024-42441 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.

CVE-2024-42440 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.

CVE-2024-42439 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.

CVE-2024-42438 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-42437 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-42436 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-42435 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVE-2024-42434 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVE-2024-39825 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

CVE-2024-39824 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVE-2024-39823 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.

CVE-2024-39822 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.

CVE-2024-39818 zoom vulnerability CVSS: 0 14 Aug 2024, 17:15 UTC

Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.

CVE-2024-24693 zoom vulnerability CVSS: 0 13 Mar 2024, 20:15 UTC

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

CVE-2024-24692 zoom vulnerability CVSS: 0 13 Mar 2024, 20:15 UTC

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

CVE-2024-24699 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

CVE-2024-24698 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

CVE-2024-24697 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2024-24696 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2024-24695 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2024-24691 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVE-2024-24690 zoom vulnerability CVSS: 0 14 Feb 2024, 00:15 UTC

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-49647 zoom vulnerability CVSS: 0 12 Jan 2024, 22:15 UTC

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2023-49646 zoom vulnerability CVSS: 0 13 Dec 2023, 23:15 UTC

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-43586 zoom vulnerability CVSS: 0 13 Dec 2023, 23:15 UTC

Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.

CVE-2023-43585 zoom vulnerability CVSS: 0 13 Dec 2023, 23:15 UTC

Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2023-43583 zoom vulnerability CVSS: 0 13 Dec 2023, 23:15 UTC

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.

CVE-2023-43591 zoom vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2023-43590 zoom vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2023-43588 zoom vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

CVE-2023-43582 zoom vulnerability CVSS: 0 15 Nov 2023, 00:15 UTC

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-39206 zoom vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39205 zoom vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39204 zoom vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39203 zoom vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2023-39202 zoom vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

CVE-2023-39199 zoom vulnerability CVSS: 0 14 Nov 2023, 23:15 UTC

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

CVE-2023-39215 zoom vulnerability CVSS: 0 12 Sep 2023, 20:15 UTC

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39208 zoom vulnerability CVSS: 0 12 Sep 2023, 20:15 UTC

Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39201 zoom vulnerability CVSS: 0 12 Sep 2023, 20:15 UTC

Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.

CVE-2023-39214 zoom vulnerability CVSS: 0 08 Aug 2023, 22:15 UTC

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-39213 zoom vulnerability CVSS: 0 08 Aug 2023, 22:15 UTC

Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-39212 zoom vulnerability CVSS: 0 08 Aug 2023, 22:15 UTC

Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

CVE-2023-39211 zoom vulnerability CVSS: 0 08 Aug 2023, 22:15 UTC

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

CVE-2023-39210 zoom vulnerability CVSS: 0 08 Aug 2023, 22:15 UTC

Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.

CVE-2023-39209 zoom vulnerability CVSS: 0 08 Aug 2023, 22:15 UTC

Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

CVE-2023-39218 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-39217 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-39216 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-36541 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.

CVE-2023-36540 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-36535 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

CVE-2023-36534 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-36533 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-36532 zoom vulnerability CVSS: 0 08 Aug 2023, 18:15 UTC

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-36538 zoom vulnerability CVSS: 0 11 Jul 2023, 18:15 UTC

Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-36537 zoom vulnerability CVSS: 0 11 Jul 2023, 18:15 UTC

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-36536 zoom vulnerability CVSS: 0 11 Jul 2023, 18:15 UTC

Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-34119 zoom vulnerability CVSS: 0 11 Jul 2023, 18:15 UTC

Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-34118 zoom vulnerability CVSS: 0 11 Jul 2023, 18:15 UTC

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-34116 zoom vulnerability CVSS: 0 11 Jul 2023, 17:15 UTC

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVE-2023-36539 zoom vulnerability CVSS: 0 30 Jun 2023, 03:15 UTC

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-34115 zoom vulnerability CVSS: 0 13 Jun 2023, 19:15 UTC

Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.

CVE-2023-34114 zoom vulnerability CVSS: 0 13 Jun 2023, 19:15 UTC

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2023-34122 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Improper input validation in the installer for Zoom for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2023-34121 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.

CVE-2023-34120 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.

CVE-2023-34113 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Insufficient verification of data authenticity in Zoom for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.

CVE-2023-28603 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.

CVE-2023-28602 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVE-2023-28601 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client.

CVE-2023-28600 zoom vulnerability CVSS: 0 13 Jun 2023, 18:15 UTC

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.

CVE-2023-28599 zoom vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.

CVE-2023-28598 zoom vulnerability CVSS: 0 13 Jun 2023, 17:15 UTC

Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.

CVE-2023-28597 zoom vulnerability CVSS: 0 27 Mar 2023, 21:15 UTC

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

CVE-2023-28596 zoom vulnerability CVSS: 0 27 Mar 2023, 21:15 UTC

Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to privileges to root.

CVE-2023-22883 zoom vulnerability CVSS: 0 16 Mar 2023, 21:15 UTC

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.

CVE-2023-22882 zoom vulnerability CVSS: 0 16 Mar 2023, 21:15 UTC

Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

CVE-2023-22881 zoom vulnerability CVSS: 0 16 Mar 2023, 21:15 UTC

Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.

CVE-2023-22880 zoom vulnerability CVSS: 0 16 Mar 2023, 21:15 UTC

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsoft’s telemetry behavior.

CVE-2022-36930 zoom vulnerability CVSS: 0 09 Jan 2023, 19:15 UTC

Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.

CVE-2022-36929 zoom vulnerability CVSS: 0 09 Jan 2023, 19:15 UTC

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

CVE-2022-36928 zoom vulnerability CVSS: 0 09 Jan 2023, 19:15 UTC

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.

CVE-2022-36927 zoom vulnerability CVSS: 0 09 Jan 2023, 19:15 UTC

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-36926 zoom vulnerability CVSS: 0 09 Jan 2023, 19:15 UTC

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-36925 zoom vulnerability CVSS: 0 09 Jan 2023, 19:15 UTC

Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service.

CVE-2022-36924 zoom vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

CVE-2022-28768 zoom vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

CVE-2022-28766 zoom vulnerability CVSS: 0 17 Nov 2022, 23:15 UTC

Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.

CVE-2022-28764 zoom vulnerability CVSS: 0 14 Nov 2022, 21:15 UTC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

CVE-2022-28763 zoom vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.

CVE-2022-28762 zoom vulnerability CVSS: 0 14 Oct 2022, 15:15 UTC

Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.

CVE-2022-28761 zoom vulnerability CVSS: 0 14 Oct 2022, 15:15 UTC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

CVE-2022-28760 zoom vulnerability CVSS: 0 14 Oct 2022, 15:15 UTC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-28759 zoom vulnerability CVSS: 0 14 Oct 2022, 15:15 UTC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-28758 zoom vulnerability CVSS: 0 16 Sep 2022, 22:15 UTC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-28757 zoom vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-28752 zoom vulnerability CVSS: 0 17 Aug 2022, 22:15 UTC

Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

CVE-2022-28751 zoom vulnerability CVSS: 0 17 Aug 2022, 22:15 UTC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-28756 zoom vulnerability CVSS: 0 15 Aug 2022, 23:15 UTC

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-28755 zoom vulnerability CVSS: 0 11 Aug 2022, 15:15 UTC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.

CVE-2022-28754 zoom vulnerability CVSS: 0 11 Aug 2022, 15:15 UTC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-28753 zoom vulnerability CVSS: 0 11 Aug 2022, 15:15 UTC

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVE-2022-28750 zoom vulnerability CVSS: 0 11 Aug 2022, 15:15 UTC

Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this vulnerability could also be leveraged to execute arbitrary code.

CVE-2022-28749 zoom vulnerability CVSS: 4.0 15 Jun 2022, 21:15 UTC

Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of the host.

CVE-2022-22788 zoom vulnerability CVSS: 6.9 15 Jun 2022, 21:15 UTC

The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.

CVE-2022-22787 zoom vulnerability CVSS: 6.0 18 May 2022, 17:15 UTC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting users client to connect to a malicious server when attempting to use Zoom services.

CVE-2022-22786 zoom vulnerability CVSS: 6.8 18 May 2022, 16:15 UTC

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.

CVE-2022-22785 zoom vulnerability CVSS: 6.4 18 May 2022, 16:15 UTC

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVE-2022-22784 zoom vulnerability CVSS: 5.5 18 May 2022, 16:15 UTC

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.

CVE-2022-22783 zoom vulnerability CVSS: 5.0 28 Apr 2022, 15:15 UTC

A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

CVE-2022-22782 zoom vulnerability CVSS: 6.6 28 Apr 2022, 15:15 UTC

The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the user’s host machine.

CVE-2022-22781 zoom vulnerability CVSS: 5.0 28 Apr 2022, 15:15 UTC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

CVE-2022-22780 zoom vulnerability CVSS: 7.8 09 Feb 2022, 23:15 UTC

The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources.

CVE-2021-34425 zoom vulnerability CVSS: 4.0 14 Dec 2021, 20:15 UTC

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s "link preview" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.

CVE-2021-34424 zoom vulnerability CVSS: 5.0 24 Nov 2021, 17:15 UTC

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom on-premise Meeting Connector before version 4.8.12.20211115, Zoom on-premise Meeting Connector MMR before version 4.8.12.20211115, Zoom on-premise Recording Connector before version 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector before version 4.4.7266.20211117, Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64 which potentially allowed for the exposure of the state of process memory. This issue could be used to potentially gain insight into arbitrary areas of the product's memory.

CVE-2021-34423 zoom vulnerability CVSS: 7.5 24 Nov 2021, 17:15 UTC

A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom On-Premise Meeting Connector Controller before version 4.8.12.20211115, Zoom On-Premise Meeting Connector MMR before version 4.8.12.20211115, Zoom On-Premise Recording Connector before version 5.1.0.65.20211116, Zoom On-Premise Virtual Room Connector before version 4.4.7266.20211117, Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64. This can potentially allow a malicious actor to crash the service or application, or leverage this vulnerability to execute arbitrary code.

CVE-2021-34418 zoom vulnerability CVSS: 5.0 11 Nov 2021, 23:15 UTC

The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.

CVE-2021-34417 zoom vulnerability CVSS: 9.0 11 Nov 2021, 23:15 UTC

The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.

CVE-2021-34416 zoom vulnerability CVSS: 7.5 27 Sep 2021, 14:15 UTC

The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.

CVE-2021-34415 zoom vulnerability CVSS: 7.8 27 Sep 2021, 14:15 UTC

The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.

CVE-2021-34414 zoom vulnerability CVSS: 6.5 27 Sep 2021, 14:15 UTC

The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.

CVE-2021-34413 zoom vulnerability CVSS: 6.0 27 Sep 2021, 14:15 UTC

All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application to execute in a privileged context.

CVE-2021-34412 zoom vulnerability CVSS: 4.6 27 Sep 2021, 14:15 UTC

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

CVE-2021-34411 zoom vulnerability CVSS: 4.6 27 Sep 2021, 14:15 UTC

During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

CVE-2021-34410 zoom vulnerability CVSS: 7.2 27 Sep 2021, 14:15 UTC

A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.0521 allows for privilege escalation to root.

CVE-2021-34409 zoom vulnerability CVSS: 7.2 27 Sep 2021, 14:15 UTC

It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.

CVE-2021-34408 zoom vulnerability CVSS: 4.6 27 Sep 2021, 14:15 UTC

The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.

CVE-2021-33907 zoom vulnerability CVSS: 10.0 27 Sep 2021, 14:15 UTC

The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

CVE-2021-30480 zoom vulnerability CVSS: 9.0 09 Apr 2021, 23:15 UTC

Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.

CVE-2021-28133 zoom vulnerability CVSS: 4.3 18 Mar 2021, 14:15 UTC

Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the participant never attempted to share the private part of their screen. When a user shares a specific application window via the Share Screen functionality, other meeting participants can briefly see contents of other application windows that were explicitly not shared. The contents of these other windows can (for instance) be seen for a short period of time when they overlay the shared window and get into focus. (An attacker can, of course, use a separate screen-recorder application, unsupported by Zoom, to save all such contents for later replays and analysis.) Depending on the unintentionally shared data, this short exposure of screen contents may be a more or less severe security issue.

CVE-2020-9767 zoom vulnerability CVSS: 7.2 14 Aug 2020, 18:15 UTC

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

CVE-2020-6110 zoom vulnerability CVSS: 6.8 08 Jun 2020, 14:15 UTC

An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.

CVE-2020-6109 zoom vulnerability CVSS: 7.5 08 Jun 2020, 14:15 UTC

An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.

CVE-2020-11877 zoom vulnerability CVSS: 5.0 17 Apr 2020, 16:15 UTC

airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code

CVE-2020-11876 zoom vulnerability CVSS: 5.0 17 Apr 2020, 16:15 UTC

airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code

CVE-2020-11500 zoom vulnerability CVSS: 5.0 03 Apr 2020, 13:15 UTC

Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key.

CVE-2020-11470 zoom vulnerability CVSS: 2.1 01 Apr 2020, 22:15 UTC

Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.

CVE-2020-11469 zoom vulnerability CVSS: 7.2 01 Apr 2020, 22:15 UTC

Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot.

CVE-2019-13567 zoom vulnerability CVSS: 6.8 12 Jul 2019, 04:15 UTC

The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.

CVE-2019-13450 zoom vulnerability CVSS: 4.3 09 Jul 2019, 06:15 UTC

In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.

CVE-2019-13449 zoom vulnerability CVSS: 4.3 09 Jul 2019, 06:15 UTC

In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.

CVE-2018-15715 zoom vulnerability CVSS: 7.5 30 Nov 2018, 20:29 UTC

Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauthorized message processing. A remote unauthenticated attacker can spoof UDP messages from a meeting attendee or Zoom server in order to invoke functionality in the target client. This allows the attacker to remove attendees from meetings, spoof messages from users, or hijack shared screens.

CVE-2017-15049 zoom vulnerability CVSS: 9.3 19 Dec 2017, 15:29 UTC

The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

CVE-2017-15048 zoom vulnerability CVSS: 6.8 19 Dec 2017, 15:29 UTC

Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

CVE-2014-5811 zoom vulnerability CVSS: 5.4 09 Sep 2014, 10:55 UTC

The ZOOM Cloud Meetings (aka us.zoom.videomeetings) application @7F060008 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2004-0680 zoom vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access.