vulnerability
Zoom Zoom: CVE-2023-36539: Exposure of Sensitive Information
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:N/AC:M/Au:S/C:C/I:N/A:N) | Jun 29, 2023 | Jan 8, 2025 | Feb 9, 2026 |
Severity
6
CVSS
(AV:N/AC:M/Au:S/C:C/I:N/A:N)
Published
Jun 29, 2023
Added
Jan 8, 2025
Modified
Feb 9, 2026
Description
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.Zoom encrypts in-meeting chat messages using a per-meeting key and then transmits these encrypted messages between user devices and Zoom using TLS encryption. In the affected products, a copy of each in-meeting chat message was also sent encrypted only using TLS and not with the per-meeting key, including messages sent during End-to-End Encrypted (E2EE) meetings.Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates fromhttps://zoom.us/download, and avoid using the in-meeting chat while on the affected versions.
Solution
zoom-zoom-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.