Google experts found 2 flaws in video conferencing software Zoom

Google Project Zero researchers have discovered two vulnerabilities in the video conferencing software Zoom that expose users to attacks.

Security researchers from Google Project Zero discovered two vulnerabilities in the video conferencing software Zoom that expose users to attacks. The vulnerabilities impact Zoom Client for Meetings on Windows, macOS, Linux, iOS, and Android.

The issues in the video conferencing software Zoom were discovered by Google Project Zero researcher Natalie Silvanovich. The first flaw, tracked as CVE-2021-34423, is a high-severity buffer overflow vulnerability that received a CVSS base score of 7.3.

“A buffer overflow vulnerability was discovered in the products listed in the “Affected Products” section of this bulletin. This can potentially allow a malicious actor to crash the service or application, or leverage this vulnerability to execute arbitrary code.” reads the security advisory published by Zoom.

The second vulnerability addressed by the company is a memory corruption issue, tracked as CVE-2021-34424, that received a CVSS base score of 7.3.

“A vulnerability was discovered in the products listed in the “Affected Products” section of this bulletin which potentially allowed for the exposure of the state of process memory. This issue could be used to potentially gain insight into arbitrary areas of the product’s memory.” reads the advisory.

Below is the list of affected Zoom products:

Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4Zoom Client for Meetings for Chrome OS before version 5.0.1Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3Zoom VDI before version 5.8.4Zoom Meeting SDK for Android before version 5.7.6.1922Zoom Meeting SDK for iOS before version 5.7.6.1082Zoom Meeting SDK for macOS before version 5.7.6.1340Zoom Meeting SDK for Windows before version 5.7.6.1081Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2Zoom On-Premise Meeting Connector Controller before version 4.8.12.20211115Zoom On-Premise Meeting Connector MMR before version 4.8.12.20211115Zoom On-Premise Recording Connector before version 5.1.0.65.20211116Zoom On-Premise Virtual Room Connector before version 4.4.7266.20211117Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117Zoom Hybrid Zproxy before version 1.0.1058.20211116Zoom Hybrid MMR before version 4.6.20211116.131_x86-64Follow me on Twitter: @securityaffairs and Facebook

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}
Pierluigi Paganini

(SecurityAffairs – hacking, video conferencing software Zoom)

The post Google experts found 2 flaws in video conferencing software Zoom appeared first on Security Affairs.