Skip to content

Latest commit

 

History

History
21 lines (11 loc) · 1.13 KB

CLVD-2020-02.md

File metadata and controls

21 lines (11 loc) · 1.13 KB

[CLVD-2020-02] Zoom Waiting Room Key Disclosure

Product Affected

Zoom for Mac, Linux, and Windows < 4.6.10

Summary

If a Zoom host enables the waiting room feature for a meeting, then the host must vet potential attendees before they are allowed into the meeting. Prospective attendees in the waiting room see a blank screen with a message: “Please wait, the meeting host will let you in soon” (Figure 1). If the meeting host approves the attendee, then they will be admitted to the meeting. We discovered that unapproved users in a Zoom waiting room had access to the meeting’s AES-128 key, as well as a live video stream (but not an audio stream) of the meeting. Though this video stream was not displayed in the Zoom UI, an unapproved user could have extracted and decrypted the video from their Internet traffic

Impact

Unapproved users would be able decrypt video of private calls without authorization.

Disclosure Timeline

  • Apr 8th, 2020 - report published