Input validation error in Zoom Workplace Desktop App for Windows - #VU29632

 

Input validation error in Zoom Workplace Desktop App for Windows - #VU29632

Published: July 10, 2020 / Updated: July 12, 2020


Vulnerability identifier: #VU29632
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input, related to video call feature. A remote attacker can trick the victim to join a conference and turn on the camera to execute arbitrary code on the system.

Note, the vulnerability affects Zoom installations on Microsoft Windows 7 and older operating systems, that are no longer supportde by Microsoft.


Affected software

Zoom Workplace Desktop App for Windows

Remediation

Install update from vendor's website.

Zoom Workplace Desktop App for Windows - update to 5.1.3 28656.0709

External References

Related Security Bulletins