CVE-2020-11500
https://notcve.org/view.php?id=CVE-2020-11500
Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key. Zoom Client for Meetings versiones hasta 4.6.9, usa el modo ECB de AES para el cifrado de video y audio. Dentro de una reunión, todos los participantes usan una única clave de 128 bits. • https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2020-11469
https://notcve.org/view.php?id=CVE-2020-11469
Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privileges) to obtain root access by replacing runwithroot. Zoom Client for Meetings versiones hasta 4.6.8 en macOS, copia runwithroot a un directorio temporal escribible por el usuario durante la instalación, lo cual permite que un proceso local (con los privilegios del usuario) obtenga acceso root mediante el reemplazo de runwithroot. • https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users https://objective-see.com/blog/blog_0x56.html • CWE-552: Files or Directories Accessible to External Parties •
CVE-2020-11470
https://notcve.org/view.php?id=CVE-2020-11470
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access. Zoom Client for Meetings versiones hasta 4.6.8 en macOS, posee el derecho de comprobación de biblioteca deshabilitado, lo cual permite un proceso local (con los privilegios del usuario) para obtener acceso improvisado de micrófono y cámara al cargar una biblioteca diseñada y heredar así el acceso al micrófono y la cámara de Zoom Client. • https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users https://objective-see.com/blog/blog_0x56.html • CWE-345: Insufficient Verification of Data Authenticity •