HomeSecurityZoom: Warns of critical vulnerability - Update immediately!

Zoom: Warns of critical vulnerability – Update immediately!

Zoom Video Communications is warning that Zoom desktop and VDI clients and the Meeting SDK for Windows are vulnerable to a vulnerability that could allow an unauthorized attacker to gain privilege escalation on the system.

zoom vulnerability update

Zoom has become one of the most popular video conferencing services during the pandemic. It is cloud-based and is used by users around the world for corporate meetings, training courses, social interactions, and more. It offers various features that enable effective digital communication and collaboration.

The vulnerability recently disclosed by the company, tracked as CVE-2024-24691 and discovered by Zoom's own security team, is considered " critical " with a CVSS v3.1 score of 9.6/10.

See also: Microsoft Patch Tuesday February 2024: 73 vulnerabilities fixed

The vulnerability affects the following product versions:

  • Zoom Desktop Client for Windows before version 5.16.5
  • Zoom VDI Client for Windows prior to version 5.16.10 (excluding 5.14.14 and 5.15.12)
  • Zoom Rooms Client for Windows before version 5.17.0
  • Zoom Meeting SDK for Windows before version 5.16.5

Zoom did not provide details on how the vulnerability is exploited or the impact, but it appears that some interaction user. This could include clicking on a link, opening an attached file, or performing some other action that an attacker could leverage to exploit the CVE-2024-24691 vulnerability.

Zoom displays an automatic notification to users to update their software to the latest version. However, one can download and install the latest version of the desktop client for Windows, version 5.17.7, manually.

It is worth noting that the immediate implementation of the update is necessary because in addition to the above critical vulnerability, six other vulnerabilities are also fixed.

See also: CISA: Adds Chrome vulnerability to KEV List

  • CVE-2024-24697: A very serious vulnerability in Zoom 32-bit Windows clients allows elevation of privilege via local access.
  • CVE-2024-24696: This is an in-meeting chat issue in Zoom Windows clients, caused by improper input validation and allowing information disclosure over the network.
  • CVE-2024-24695: Similar to CVE-2024-24696, improper input validation in Zoom Windows clients allows information disclosure over the network.
  • CVE-2024-24699: A business logic error in the in-meeting chat feature that could lead to information disclosure over the network.
  • CVE-2024-24698: A vulnerability that allows information disclosure through local access by privileged users.
Zoom: Warns of critical vulnerability - Update immediately!

Protection

Considering the above vulnerabilities, Zoom users should apply the security update as soon as possible to reduce the chances of a breach.

See also: New vulnerabilities in Cisco, Fortinet, VMware require immediate updates

Next, it's helpful to have a reliable antivirus program installed on your device . This can help detect and prevent attacks before they cause damage.

Finally, use a firewall to control incoming and outgoing traffic on your network. This can help prevent attacks before they reach your system.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS