Zoom patches critical account takeover vulnerability

This digest was compiled by AI from multiple sources — links to the originals are below.
Zoom patched a critical security flaw that could allow an unauthenticated attacker to take over accounts via network access. The bug affects Windows clients and was disclosed alongside three privilege escalation issues. No active exploitation has been reported, according to IDC.
The Vulnerability
Zoom patched a critical account takeover hole that allows an unauthenticated attacker to gain control via network access, with low complexity and no user interaction required. The bug affects Zoom Desktop Client for Windows before version 7.0.0, VDI Client for Windows before versions 7.0.10, 6.6.15, and 6.5.18, and initially the Meeting SDK for Windows, which Zoom later removed from the affected list without explanation. IDC's Frank Dickson described the flaw as "as bad as it gets, short of a worm."
Additional Patches
Zoom also fixed three privilege escalation vulnerabilities impacting Zoom Workplace for Windows before 7.0.5, VDI Client and Plugin for Windows before 6.5.17 and 6.6.14, Zoom Rooms for Windows before 7.0.5 and 7.1.0, and Remote Control for Zoom Contact Center for Windows before 7.0.0. These issues are less severe but still significant, according to Zoom's security bulletins released Tuesday.
Expert Concerns
Brian Levine of FormerGov warned that an attacker with account access could listen to sensitive recordings, eavesdrop on future meetings, and impersonate organizations to social-engineer clients. Zoom has over 300 million daily active users and 470,000 paying business customers, making the flaw particularly concerning. France previously attempted to ban Zoom for government use.