Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwhj-68xr-qf9r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.

Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.

EPSS

Процентиль: 22%
0.00071
Низкий

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.3
nvd
почти 6 лет назад

Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.

EPSS

Процентиль: 22%
0.00071
Низкий

Дефекты

CWE-862