ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Zoom Patches High

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-28762
Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration.

Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.

NVD description · AI analysis pending
7.8<1%
  • zoom meetings
Full article294 words · extracted from infosecurity-magazine.com · click to collapse

Video messaging platform Zoom released a new patch last week to a high-severity flaw in its client for macOS devices.

The vulnerability (tracked CVE-2022-28762) refers to a debugging port misconfiguration affecting versions between 5.10.6 and 5.12.0 (excluded) and has a common vulnerability scoring system (CVSS) of 3.1 of 7.3 out of 10.

“When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client,” the company wrote on its security bulletin page last week.

According to the video messaging firm, if exploited, the flaw could allow a malicious actor to connect to their client and control the Zoom Apps running in it.

From a technical standpoint, Zoom Apps are integrations with external apps that users can access from within the video messaging platform. They include tools such as Miro, Dropbox Spaces and Asana, among others.

The flaw has been spotted by Zoom’s own security team and fully patched in the latest version of the macOS client (5.12.0), which is now available on the company’s website and via settings in already installed iterations of the video messaging platform.

“Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates,” the tech firm wrote.

The security bulletin comes months after Ivan Fratric from Google Project Zero discovered four vulnerabilities (now patched) that could be exploited to compromise users over chat by sending certain Extensible Messaging and Presence Protocol (XMPP) messages and executing malicious code.

More recently, an investigation by cybersecurity company Cyfirma suggested the threat actors known as FIN11 (and Clop) may have impersonated web download pages of the Zoom application to run phishing campaigns against targets worldwide.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/zoom-patches-high-severity-flaw-in/