Zoom Alert
3024Warning Date
Severity Level
Warning Number
Target Sector
10 August, 2022
● Critical
2022-5108
All
Description:
Zoom has released security updates to address several vulnerabilities in the following products:
- Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112
- Zoom Rooms for Conference Room Windows before version 5.11.0
- Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0
- Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714
- Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Execute arbitrary code remotely
- Escalation of privilege
- Improper Access Control
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review Zoom security advisory and apply the necessary updates:
Update instructions:
- Sign in to Zoom desktop client
- Click your profile picture then click Check for Updates
- If there is a newer version, Zoom will download and install it.