Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://objective-see.com/blog/blog_0x56.html | third party advisory exploit |
https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/ | vendor advisory |