Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Zoom Rooms was affected by four “high” severity vulnerabilities

Zoom addressed four “high” severity vulnerabilities impacting its popular videoconferencing software Zoom Rooms. Zoom addressed four “high” severity vulnerabilities impacting its videoconferencing platform Zoom Rooms. Below are the details for the bugs addressed by the company: CVE-2022-36930 (CVSS Score 8.2) – Local Privilege Escalation in Rooms for Windows Installers. The issue affects Rooms for Windows […]

Zoom Zoomsday

Zoom addressed four “high” severity vulnerabilities impacting its popular videoconferencing software Zoom Rooms.

Zoom addressed four “high” severity vulnerabilities impacting its videoconferencing platform Zoom Rooms.

Below are the details for the bugs addressed by the company:

CVE-2022-36930 (CVSS Score 8.2) – Local Privilege Escalation in Rooms for Windows Installers.

The issue affects Rooms for Windows installers before version 5.13.0.

“A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.” reads the advisory published by the company.

CVE-2022-36929 – (CVSS Score 7.8) – Local Privilege Escalation in Rooms for Windows Clients.

The flaw affects Rooms for Windows clients before version 5.12.7. A local low-privileged user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

CVE-2022-36926 – CVE-2022-36927 – (CVSS Score 8.8) – Local Privilege Escalation in Zoom Rooms for macOS Clients. The flaw affects Rooms for macOS clients before version 5.11.3. The issue can be exploited by a local low-privileged user to escalate their privileges to root.

zoom rooms CVE-2022-28762

The communications technology company also addressed two “Medium” severity bugs:

  • CVE-2022-36928 – (CVSS Score 6.1) – Path Traversal in Zoom for Android Clients.
  • CVE-2022-36925 – (CVSS Score 4.4) – Insecure key generation for Zoom Rooms for macOS Clients

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Rooms)

[adrotate banner=”5″]

[adrotate banner=”13″]