High severity7.5NVD Advisory· Published Apr 17, 2020· Updated Jun 17, 2026
CVE-2020-11877
CVE-2020-11877
Description
airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code
Affected products
3- cpe:2.3:a:zoom:meetings:4.6.11:*:*:*:*:windows:*:*
- Zoom/Client for Meetingsdescription
- Range: 4.6.11
Patches
Vulnerability mechanics
References
1- dev.io/posts/zoomzoo/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.