Friday, November 22, 2024
HomeCyber Security NewsBeware! Hackers Can Now Exploit a Security Flaw in Zoom Client

Beware! Hackers Can Now Exploit a Security Flaw in Zoom Client

Published on

The popular video messaging platform Zoom has discovered multiple vulnerabilities affecting Zoom Clients. These vulnerabilities might allow an unauthorized user to carry out denial-of-service, privilege escalation, and information disclosure attacks.

To receive the most recent security updates and bug fixes, Zoom advises users to update to the most recent version of the Zoom software.

High Severity Vulnerabilities Impacting Zoom Clients

Improper Authentication – CVE-2023-39215

- Advertisement - SIEM as a Service

With a CVSS Base Score of 7.1 and a High severity vulnerability listed as CVE-2023-39215, improper authentication in Zoom clients may enable an authenticated user to utilize network access to perform a denial of service attack.

Affected Products:

  • Zoom Desktop Client for Windows before version 5.15.5
  • Zoom Desktop Client for macOS before version 5.15.5
  • Zoom Desktop Client for Linux before version 5.15.5
  • Zoom VDI Client before version 5.14.12
  • Zoom VDI Client before version 5.15.4
  • Zoom Mobile App for Android before version 5.15.5
  • Zoom Mobile App for iOS before version 5.15.5
  • Zoom Meeting SDK’s before version 5.15.5

Exposure of Sensitive Information – CVE-2023-39214

A high-severity vulnerability with a CVSS Base Score of 7.6 is identified as CVE-2023-39214. It involves the exposure of sensitive data in Zoom Client versions before 5.15.5, which could enable a denial of service via network access for an authenticated user.

Affected Products:

  • Zoom Desktop Client for Windows before version 5.15.5
  • Zoom Desktop Client for macOS before version 5.15.5
  • Zoom Desktop Client for Linux before version 5.15.5
  • Zoom Mobile App for Android before version 5.15.5
  • Zoom Mobile App for iOS before version 5.15.5
  • Zoom Rooms for iPad before version 5.15.5
  • Zoom Rooms for Android before version 5.15.5
  • Zoom Rooms for Windows before version 5.15.5
  • Zoom Rooms for macOS before version 5.15.5

Client-Side Enforcement of Server-Side Security – CVE-2023-36535

Before version 5.14.10, client-side enforcement of server-side security in Zoom clients may have allowed an authenticated user to enable information exposure via network access.

This high-severity vulnerability was identified as CVE-2023-36535 and has a CVSS Base Score of 7.1.

Affected Products:

  • Zoom Clients for Windows before version 5.14.10
  • Zoom Desktop Client for macOS before version 5.14.10
  • Zoom Desktop Client for Linux before version 5.14.10
  • Zoom VDI Host and Plugin before version 5.14.10
  • Zoom Mobile App for Android before version 5.14.10
  • Zoom Mobile App for iOS before version 5.14.10
  • Zoom Rooms for iPad before version 5.14.10
  • Zoom Rooms for Android before version 5.14.10
  • Zoom Rooms for Windows before version 5.14.10
  • Zoom Rooms for macOS before version 5.14.10

Medium and Low-Severity Vulnerabilities Impacting Zoom Clients

Improper Authorization (CVE-2023-43582), Insufficient Control Flow Management (CVE-2023-43588), Cryptographic Issues (CVE-2023-39199), Buffer Overflow (CVE-2023-39206, CVE-2023-39204, CVE-2023-36532), Improper Conditions Check (CVE-2023-39205), 

Client-Side Enforcement of Server-Side Security (CVE-2023-39218), Improper Input Validation (CVE-2023-39217).

Update Now!

Users are advised to stay safe by installing the most recent updates or getting the most recent Zoom software which includes all security updates.

Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Halo Security Launches Slack Integration for Real-Time Alerts on New Assets and Vulnerabilities

Halo Security, a leader in external attack surface management and penetration testing, has announced...

Researchers Detailed FrostyGoop Malware Attacking ICS Devices

FrostyGoop, a newly discovered OT-centric malware that exploited Modbus TCP to disrupt critical infrastructure...

5 Hackers Charged for Attacking Companies via Phishing Text Messages

Federal authorities have unsealed charges against five individuals accused of orchestrating sophisticated phishing schemes...

Two PyPi Malicious Package Mimic ChatGPT & Claude Steals Developers Data

Two malicious Python packages masquerading as tools for interacting with popular AI models ChatGPT...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Researchers Detailed FrostyGoop Malware Attacking ICS Devices

FrostyGoop, a newly discovered OT-centric malware that exploited Modbus TCP to disrupt critical infrastructure...

5 Hackers Charged for Attacking Companies via Phishing Text Messages

Federal authorities have unsealed charges against five individuals accused of orchestrating sophisticated phishing schemes...

Two PyPi Malicious Package Mimic ChatGPT & Claude Steals Developers Data

Two malicious Python packages masquerading as tools for interacting with popular AI models ChatGPT...