Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the users privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Clients microphone and camera access.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Meetings | Zoom | * | 4.6.8 (including) |