CERT-In Vulnerability Note
CIVN-2023-0396
Multiple Vulnerabilities in Zoom
Original Issue Date:December 29, 2023
Severity Rating: HIGH
Software Affected
- Zoom Desktop Client for Windows prior version 5.16.5
- Zoom Desktop Client for macOS prior version 5.16.5
- Zoom Mobile App for iOS prior version 5.16.5
- Zoom Mobile App for Android prior version 5.16.5
- Zoom Desktop Client for Linux prior version 5.16.5
- Zoom VDI Client prior version 5.16.5 (excluding 5.14.14 and 5.15.12)
- Zoom SDKs prior version 5.16.5
- Zoom Video SDK for Windows prior version 5.16.5
- Zoom Video SDK for iOS prior version 5.16.5
- Zoom Video SDK for Android prior version 5.16.0
- Zoom Meeting SDK for Windows prior version 5.16.5
- Zoom Meeting SDK for iOS prior version 5.16.5
- Zoom Meeting SDK for Android prior version 5.16.0
- Zoom Meeting SDK for iOS prior version 5.16.0
Overview
Multiple vulnerabilities have been reported in Zoom products, which could allow an authenticated user to perform denial of service, escalate privileges or disclose information on the targeted system.
Description
These vulnerabilities exist in Zoom products due to improper authentication, path traversal, improper access control and cryptographic issues.
Successful exploitation of these vulnerabilities could allow an authenticated user to perform denial of service, escalate privileges or disclose information on the targeted system.
Solution
Apply appropriate fix/patches as mentioned:
https://www.zoom.com/en/trust/security-bulletin/ZSB-23062/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23059/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23058/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23056/
Vendor Information
Zoom
https://www.zoom.com/en/trust/security-bulletin/ZSB-23062/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23059/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23058/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23056/
References
Zoom
https://www.zoom.com/en/trust/security-bulletin/ZSB-23062/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23059/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23058/
https://www.zoom.com/en/trust/security-bulletin/ZSB-23056/
CVE Name
CVE-2023-49646
CVE-2023-43586
CVE-2023-43585
CVE-2023-43583
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|