#VU69235 Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-28764
Published: November 11, 2022
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for Linux
Zoom Workplace Desktop App for macOS
Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Video Communications, Inc.
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the application does not clear data from the local SQL database after a meeting ends and also uses an insufficiently secure per-device key to encrypt meetings data. A local user can obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.