Application Window Screen Sharing Functionality

  • ZSB-21001
  • CVE-2021-28133
  • Medium
  • 5.7
  • CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

A vulnerability affected the Zoom Windows and Linux Clients’ share screen functionality when sharing individual application windows, in which screen contents of applications which are not explicitly shared by the screen-sharing users may be seen by other meeting participants for a brief moment if the “sharer” is minimizing, maximizing, or closing another window.

Zoom introduced several new security mitigations in Zoom Windows Client version 5.6 that reduce the possibility of this issue occurring for Windows users. We are continuing to work on additional measures to resolve this issue across all affected platforms.

Zoom also resolved the issue for Ubuntu users on March 1, 2021 in Zoom Linux Client version 5.5.4. Users can apply current updates or download the latest Zoom software with all current security updates from https://zoom.us/download.

  • All Windows Zoom Client versions
  • Linux Zoom Client versions prior to 5.5.4 on Ubuntu
  • All Linux Client versions on other supported distributions

Discovered by Michael Stramez and Matthias Deeg.

Revision Date Description
1.0 03/26/2021

Initial Publication