Tuesday, March 28, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Web Conferencing: High-Risk Gaps in Zoom

Kiratas by Kiratas
March 16, 2023
in World
Reading Time: 2 mins read
0
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

Some of the company’s developers have classified security gaps in the web conference software Zoom as high risk. Some could have enabled attackers to inject malicious code into users or to extend rights in the system. Updates to patch the leaks are ready.

Zoom: High-risk vulnerabilities

The vulnerability with the highest risk rating relates to saving a local recording to an SMB share and later opening the file using a link from the Zoom web portal. Attackers from adjacent networks could use a malicious SMB server to answer client requests and thus foist their own executable files on victims (CVE-2023-22885, CVSS 8.3Risk “hoch“).

The Windows installer from the Zoom client for IT administrators enabled attackers to extend their own rights in the system. In a chain of attacks, malicious actors could gain system privileges during the installation process (CVE-2023-22883, CVSS 7.2, hoch). A similar vulnerability can be found in the Mac installer of the Zoom client for IT admins, where local attackers could gain root privileges (CVE-2023-22884, CVSS 5.2, middle).

An update to the Microsoft Edge WebView2 component has made Zoom clients, Zoom Rooms and Zoom VDI vulnerable to an information leak on Windows. The component sent texts to Microsoft’s online spell checker instead of local proofreading. To solve the problem, the developers simply turned off the check function (2023-22880, CVSS 6.8, middle). Another vulnerability could have been abused by attackers with manipulated UDP packets to shoot down zoom clients. These crashed due to errors in the STUN parser during processing, resulting in a possible denial of service (CVE-2023-22881, CVE-2023-22882; both CVSS 6.5, middle).

Fixed issue with updated software

The vulnerabilities affect Zoom for Android, iOS, Linux, macOS and Windows prior to version 5.13.5, Zoom Rooms for Android, iOS, Linux, macOS and Windows prior to version 5.13.5, Zoom VDI Windows Meeting clients prior to the current version 5.13. 10, Zoom Client for Meetings for IT Admins Windows Installers prior to 5.13.5 and Zoom Client for Meetings for IT Admin macOS Installers prior to 5.13.5. The manufacturer lists the security notifications on the Zoom security website.

These also contain more details on the vulnerabilities and the versions specifically affected by them. Administrators can download updated software from the Zoom download website. The function for checking for updates, which can be called up in the software, should also transfer the current status to the computer.

Zoom last released software updates in January of this year. The company has also closed various security gaps in it.

(dmk)

To home page

Tags: conferencinggapsHighriskSecuritySecurity UpdatesVulnerabilitiesWebZoom

Related Posts

World

Like an elephant’s trunk: soft robotic arm for collaborative work

by Kiratas
March 28, 2023
World

Gerard Piqué humiliates Shakira by hitting him where it hurts the most: his children, in the middle of everything

by Kiratas
March 28, 2023
World

E3 2023: Game fair is on the brink after Ubisoft’s cancellation

by Kiratas
March 28, 2023
World

Becky G’s soccer player boyfriend breaks his silence… and admits to having cheated on him!

by Kiratas
March 28, 2023
World

Schufa shortens the storage period for entries on private bankruptcies

by Kiratas
March 28, 2023
Next Post

Setién's Villarreal fails in the Conference League

EU Advocate General: Schufa profiles not allowed

Spectacular train derailment in Kentucky

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank business ChatGPT Check Cybercrime data data protection day Energy EU euros February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million online photo price result Security Smartphone Software Development Spain Spanish Sánchez Test time today Vulnerabilities world year years

Recent Posts

  • Like an elephant’s trunk: soft robotic arm for collaborative work
  • Gerard Piqué humiliates Shakira by hitting him where it hurts the most: his children, in the middle of everything
  • E3 2023: Game fair is on the brink after Ubisoft’s cancellation
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.