
Video conferencing software Zoom is working to patch a zero-day vulnerability uncovered by security firm ACROS Security.
The company said the zero-day vulnerability affects the Zoom Windows client, but only when the clients are running on older versions of the Windows OS, such as Windows 7, Windows Server 2008 R2 and earlier.
Zoom clients on Windows 8 or Windows 10 are not affected, according to ACROS Security CEO Mitja Kolsek.
"The vulnerability allows a remote attacker to execute code on computer where the Zoom Client for Windows is installed by causing the user to perform some standard action, such as opening a document," Kolsek said.
"No security warning is displayed to the user during the attack," he added.
Kolsek said ACROS didn't discover the vulnerability on its own. It was tipped off by a security researcher who wanted to keep his identity a secret.
ACROS reported the zero-day vulnerability in Zoom and released an update to the 0patch client to prevent attacks on its own clients until Zoom releases an official fix. Below you can see a video, which shows how the zero-day vulnerability can be exploited and how it is blocked by the 0patch client.
ACROS did not release further technical details about the vulnerability.
“Zoom takes all reports of potential security vulnerabilities seriously. This morning we received a report of an issue affecting users running Windows 7 and earlier. We have confirmed this issue and are currently working on a patch to resolve it quickly.”
No information has been given yet regarding the release date of the update.
In recent months, Zoom has paused the release of new features to security user, as several security issues were revealed in April.
