U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Zoom Rooms was affected by four “high” severity vulnerabilities

Zoom addressed four “high” severity vulnerabilities impacting its popular videoconferencing software Zoom Rooms. Zoom addressed four “high” severity vulnerabilities impacting its videoconferencing platform Zoom Rooms. Below are the details for the bugs addressed by the company: CVE-2022-36930 (CVSS Score 8.2) – Local Privilege Escalation in Rooms for Windows Installers. The issue affects Rooms for Windows […]

Zoom Room

Zoom addressed four “high” severity vulnerabilities impacting its popular videoconferencing software Zoom Rooms.

Zoom addressed four “high” severity vulnerabilities impacting its videoconferencing platform Zoom Rooms.

Below are the details for the bugs addressed by the company:

CVE-2022-36930 (CVSS Score 8.2) – Local Privilege Escalation in Rooms for Windows Installers.

The issue affects Rooms for Windows installers before version 5.13.0.

“A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.” reads the advisory published by the company.

CVE-2022-36929 – (CVSS Score 7.8) – Local Privilege Escalation in Rooms for Windows Clients.

The flaw affects Rooms for Windows clients before version 5.12.7. A local low-privileged user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

CVE-2022-36926 – CVE-2022-36927 – (CVSS Score 8.8) – Local Privilege Escalation in Zoom Rooms for macOS Clients. The flaw affects Rooms for macOS clients before version 5.11.3. The issue can be exploited by a local low-privileged user to escalate their privileges to root.

zoom rooms CVE-2022-28762

The communications technology company also addressed two “Medium” severity bugs:

  • CVE-2022-36928 – (CVSS Score 6.1) – Path Traversal in Zoom for Android Clients.
  • CVE-2022-36925 – (CVSS Score 4.4) – Insecure key generation for Zoom Rooms for macOS Clients

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Rooms)

[adrotate banner=”5″]

[adrotate banner=”13″]