• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new zoom flaws could let attackers hack victims just by

New Zoom Flaws Could Let Attackers Hack Victims Just by Sending them a Message

You are here: Home / General Cyber Security News / New Zoom Flaws Could Let Attackers Hack Victims Just by Sending them a Message
May 25, 2022

Popular video conferencing company Zoom has settled as a lot of as 4 security vulnerabilities, which could be exploited to compromise yet another person more than chat by sending specifically crafted Extensible Messaging and Existence Protocol (XMPP) messages and execute malicious code.

Tracked from CVE-2022-22784 as a result of CVE-2022-22787, the issues range in between 5.9 and 8.1 in severity. Ivan Fratric of Google Undertaking Zero has been credited with discovering and reporting all the 4 flaws in February 2022.

CyberSecurity

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The listing of bugs is as follows –

  • CVE-2022-22784 (CVSS rating: 8.1) – Poor XML Parsing in Zoom Client for Meetings
  • CVE-2022-22785 (CVSS rating: 5.9) – Improperly constrained session cookies in Zoom Customer for Conferences
  • CVE-2022-22786 (CVSS score: 7.5) – Update package downgrade in Zoom Consumer for Conferences for Windows
  • CVE-2022-22787 (CVSS rating: 5.9) – Inadequate hostname validation in the course of server change in Zoom Client for Meetings

With Zoom’s chat performance created on prime of the XMPP normal, thriving exploitation of the issues could enable an attacker to power a vulnerable consumer to masquerade a Zoom consumer, join to a destructive server, and even down load a rogue update, resulting in arbitrary code execution stemming from a downgrade attack.

Fratric dubbed the zero-click on attack sequence as a scenario of “XMPP Stanza Smuggling,” including “one particular person could possibly be equipped to spoof messages as if coming from another consumer” and that “an attacker can send out control messages which will be accepted as if coming from the server.”

At its main, the issues choose edge of parsing inconsistencies in between XML parsers in Zoom’s shopper and server to “smuggle” arbitrary XMPP stanzas — a simple unit of interaction in XMPP — to the sufferer client.

CyberSecurity

Specifically, the exploit chain can be weaponized to hijack the software update system and make the consumer connect to a man-in-the-center server that serves up an aged, fewer secure variation of the Zoom shopper.

Even though the downgrade attack singles out the Windows variation of the application, CVE-2022-22784, CVE-2022-22785, and CVE-2022-22787 impression Android, iOS, Linux, macOS, and Windows.

The patches arrive fewer than a month soon after Zoom tackled two large-severity flaws (CVE-2022-22782 and CVE-2022-22783) that could lead to neighborhood privilege escalation and publicity of memory content in its on-premise Meeting solutions. Also preset was one more instance of a downgrade attack (CVE-2022-22781) in Zoom’s macOS app.

Consumers of the software are recommended to update to the newest edition (5.10.) to mitigate any opportunity threats arising out of active exploitation of the flaws.

Uncovered this report appealing? Comply with THN on Facebook, Twitter  and LinkedIn to go through additional distinctive content we article.


Some components of this write-up are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Ransomware Attacks Increasing at “Alarming” Rate
Next Post: 68% of Legal Sector Data Breaches Caused by Insider Threats Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.