Endpoint Vulnerability

Zoom Vulnerability CVE-2020-11470

Description

Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user\'s privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client\'s microphone and camera access.

Affected Products

Zoom

References

CVE-2020-11470,