The popular video messaging platform Zoom has discovered multiple vulnerabilities affecting Zoom Clients. These vulnerabilities might allow an unauthorized user to carry out denial-of-service, privilege escalation, and information disclosure attacks.
To receive the most recent security updates and bug fixes, Zoom advises users to update to the most recent version of the Zoom software.
Improper Authentication – CVE-2023-39215
With a CVSS Base Score of 7.1 and a High severity vulnerability listed as CVE-2023-39215, improper authentication in Zoom clients may enable an authenticated user to utilize network access to perform a denial of service attack.
Affected Products:
Exposure of Sensitive Information – CVE-2023-39214
A high-severity vulnerability with a CVSS Base Score of 7.6 is identified as CVE-2023-39214. It involves the exposure of sensitive data in Zoom Client versions before 5.15.5, which could enable a denial of service via network access for an authenticated user.
Affected Products:
Client-Side Enforcement of Server-Side Security – CVE-2023-36535
Before version 5.14.10, client-side enforcement of server-side security in Zoom clients may have allowed an authenticated user to enable information exposure via network access.
This high-severity vulnerability was identified as CVE-2023-36535 and has a CVSS Base Score of 7.1.
Affected Products:
Medium and Low-Severity Vulnerabilities Impacting Zoom Clients
Improper Authorization (CVE-2023-43582), Insufficient Control Flow Management (CVE-2023-43588), Cryptographic Issues (CVE-2023-39199), Buffer Overflow (CVE-2023-39206, CVE-2023-39204, CVE-2023-36532), Improper Conditions Check (CVE-2023-39205),
Client-Side Enforcement of Server-Side Security (CVE-2023-39218), Improper Input Validation (CVE-2023-39217).
Users are advised to stay safe by installing the most recent updates or getting the most recent Zoom software which includes all security updates.
Patch Manager Plus, the one-stop solution for automated updates of over 850 third-party applications: Try Free Trial.
Hackers have reportedly infiltrated and extracted a vast 82 GB of sensitive data from the Indonesian…
IBM has issued a security bulletin warning of two vulnerabilities in its AIX operating system…
The Apache Software Foundation has issued a security alert regarding a critical vulnerability in Apache…
The Chinese National Internet Emergency Center (CNIE) has revealed two significant cases of cyber espionage…
A critical command injection vulnerability in the popular systeminformation npm package has recently been disclosed, exposing millions…
Researchers discovered a malware campaign targeting the npm ecosystem, distributing the Skuld info stealer through…