If you are using Zoom app for video calls, then you should sit up and pay notice! India has warned about the high risk present on the video conferencing platform Zoom. Indian Computer Emergency Response Team (CERT-In) said, “Multiple vulnerabilities have been identified in Zoom products.” Attackers are getting entry into the Zoom users' system and carrying out malicious activities. According to the information provided by CERT-In, the flaws reported in the Zoom product have been exploited by an authenticated attacker to bypass security restrictions. Also, attackers have executed arbitrary code or caused a denial of service conditions on the targeted system.
“Multiple vulnerabilities have been identified in Zoom products. The flaws could be exploited by an authenticated attacker to bypass security restriction, execute arbitrary code or cause a denial of service conditions on the targeted system,” the CERT-IN report mentioned in the vulnerability note.
All Zoom users need to bring their attention to this affected version. The report has stated that the reported flaws are found on Zoom On-Premise Meeting Connector MMR which is running on version 4.8.20220916.131 and before. Also, Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 are affected by the vulnerabilities. The report by CERT-In confirms that these vulnerabilities exist due to improper access control and debugging port misconfiguration flaws.
If you are using any of these versions, then you need to worry as an authenticated user could exploit these vulnerabilities and take advantage of the debugging port to connect to and control the Zoom Apps. Not just that, hackers could also prevent users from receiving audio and
Read more on tech.hindustantimes.com