vulnerability

Zoom Zoom: CVE-2023-36539: Exposure of Sensitive Information

Severity
6
CVSS
(AV:N/AC:M/Au:S/C:C/I:N/A:N)
Published
Jun 29, 2023
Added
Jan 8, 2025
Modified
Mar 25, 2026

Description

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.Zoom encrypts in-meeting chat messages using a per-meeting key and then transmits these encrypted messages between user devices and Zoom using TLS encryption. In the affected products, a copy of each in-meeting chat message was also sent encrypted only using TLS and not with the per-meeting key, including messages sent during End-to-End Encrypted (E2EE) meetings.Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates fromhttps://zoom.us/download, and avoid using the in-meeting chat while on the affected versions.

Solution

zoom-zoom-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.