CVE-2021-28133
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-28133 is a security vulnerability discovered in Zoom video conferencing software versions through 5.5.4. The vulnerability was discovered and reported by SySS researchers Michael Strametz and Matthias Deeg on December 2, 2020. The issue affects the screen sharing functionality, where other meeting participants can briefly see contents of applications that were not explicitly shared by the user (SYSS Advisory, Hacker News).

Technical details

The vulnerability occurs when a Zoom user shares a specific application window via the 'share screen' functionality. When another application window overlays the shared window and gets into focus, its contents can be briefly visible to other meeting participants, even though it was not explicitly shared. The vulnerability was assigned a CVSS v3.1 score of 4.3 (Medium severity) and affects both Windows and Linux Zoom clients (NVD).

Impact

The security issue could lead to unintentional exposure of sensitive information. A malicious participant could use screen recording software to capture these momentarily visible windows and later analyze the recorded content at their leisure. The severity of the impact depends on the nature of the inadvertently shared data (SYSS Advisory).

Mitigation and workarounds

The vulnerability was fixed in newer versions of Zoom software released after March 23, 2021. Users are recommended to update their Zoom client to the latest version to receive the security fix (SYSS Advisory).

Community reactions

When contacted about the vulnerability, Zoom acknowledged the security issue and confirmed they were working to resolve it. A Zoom spokesperson stated to The Hacker News, "Zoom takes all reports of security vulnerabilities seriously. We are aware of this issue, and are working to resolve it" (Hacker News).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management