#VU27053 Security Features in Zoom Workplace Desktop App for Windows - CVE-2020-11876
Published: April 21, 2020 / Updated: June 30, 2020
Zoom Workplace Desktop App for Windows
Zoom Video Communications, Inc.
Description
This vulnerability allows a remote attacker to bypass security rescritions feature.
The vulnerability exists due to the "airhost.exe" uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. A remote attacker can gain unauthorized access to the application.