Multiple Vulnerabilities Reported in Zoom

Risk:
medium
Damage:
medium
Platform(s):
Zoom
Advisory ID:
ngCERT-2022-0093
Version:
N/A
CVE:
CVE-2022-28758, CVE-2022-28759, CVE-2022-28760
Published:
September 21, 2022

Summary


Zoom Products have been found to have a number of flaws by the Indian Computer Emergency Response Team (CERT-In). A remote attacker could exploit the vulnerabilities to circumvent implemented security measures and cause a denial of service on the targeted machine.

Description & Consequence


These vulnerabilities exist owing to incorrect access control implementation in Zoom On-Premise Meeting Connector MMR prior to version 4.8.20220815.130. A remote attacker could exploit these flaws to join a meeting they are permitted to attend without being seen by the other attendees. They can also access audio and video feeds from meetings they were not permitted to attend, as well as interrupt other sessions.

Exploiting these vulnerabilities successfully, potentially allow an unauthorized remote authenticated user to bypass implemented security limitations on the targeted system.

Solution


Zoom users are advised to update their Zoom software to the latest version as instructed on their official website by following: https://explore.zoom.us/en/trust/security/security-bulletin/

 

Reference


  • https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2022-0360

  • https://explore.zoom.us/en/trust/security/security-bulletin/

Revision


Related Articles