Reliance on Untrusted Inputs in a Security Decision in Zoom Workplace Desktop App for Windows - #VU26523
Published: April 1, 2020 / Updated: April 21, 2020
Zoom Workplace Desktop App for Windows
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to Zoom client for Windows automatically processes comments in chat and converts URLs with UNC path into links. A remote attacker can trick the victim into following this link and gain access to NTLM credentials, sent by the victim's system.