mimile
mimile.ai
Back to feed

Zoom patches critical account takeover vulnerability

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Zoom patches critical account takeover vulnerability

Zoom patched a critical security flaw that could allow an unauthenticated attacker to take over accounts via network access. The bug affects Windows clients and was disclosed alongside three privilege escalation issues. No active exploitation has been reported, according to IDC.

The Vulnerability

Zoom patched a critical account takeover hole that allows an unauthenticated attacker to gain control via network access, with low complexity and no user interaction required. The bug affects Zoom Desktop Client for Windows before version 7.0.0, VDI Client for Windows before versions 7.0.10, 6.6.15, and 6.5.18, and initially the Meeting SDK for Windows, which Zoom later removed from the affected list without explanation. IDC's Frank Dickson described the flaw as "as bad as it gets, short of a worm."

Additional Patches

Zoom also fixed three privilege escalation vulnerabilities impacting Zoom Workplace for Windows before 7.0.5, VDI Client and Plugin for Windows before 6.5.17 and 6.6.14, Zoom Rooms for Windows before 7.0.5 and 7.1.0, and Remote Control for Zoom Contact Center for Windows before 7.0.0. These issues are less severe but still significant, according to Zoom's security bulletins released Tuesday.

Expert Concerns

Brian Levine of FormerGov warned that an attacker with account access could listen to sensitive recordings, eavesdrop on future meetings, and impersonate organizations to social-engineer clients. Zoom has over 300 million daily active users and 470,000 paying business customers, making the flaw particularly concerning. France previously attempted to ban Zoom for government use.

What's Next

Zoom has not commented on the removal of Meeting SDK from the affected list. Analysts warn that reverse-engineering the patch could enable widespread exploitation, though no in-the-wild attacks have been reported as of Thursday.

2 sources

Zoom patches critical account takeover vulnerability