#VU26523 Reliance on Untrusted Inputs in a Security Decision in Zoom Workplace Desktop App for Windows
Published: April 1, 2020 / Updated: April 21, 2020
Zoom Workplace Desktop App for Windows
Zoom Video Communications, Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to Zoom client for Windows automatically processes comments in chat and converts URLs with UNC path into links. A remote attacker can trick the victim into following this link and gain access to NTLM credentials, sent by the victim's system.