Zoom Releases Security Updates
Security updates address four vulnerabilities, with one that could allow users to be spoofed and one that could allow arbitrary code execution
Summary
Security updates address four vulnerabilities, with one that could allow users to be spoofed and one that could allow arbitrary code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Zoom has released security updates addressing four vulnerabilities, two that are considered medium and two that are considered high impact. An attacker could compromise users over chat by sending a specially crafted Extensible Messaging and Presence Protocol (XMPP) message, execute arbitrary code, and take control of a system.
Remediation advice
Affected organisations are encouraged to review the following Zoom security advisory and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 26 May 2022 5:01 pm