https://news.rambler.ru/img/2020/07/10/091629.927645.5462.jpg

Slovenian security company ACROS Security has disclosed a vulnerability in software conferencing Zoom that could allow an attacker to remotely execute code on the computer running the affected client Zoom for Windows. The problem only affects users of older versions of Microsoft OS, such as Windows 7, Windows Server 2008 R2 and earlier. The users of Windows 8 and Windows 10 is nothing to worry about.

As explained by the head ACROS Security Kolsek Mitya (Mitja Kolsek), an attacker could remotely execute code on the system with the default Zoom for Windows client, forcing the victim to perform certain actions (e.g. to open a document file). In the process exploit any notification and alert will not be displayed.

The vulnerability was discovered by an unknown security researcher, who asked to remain anonymous. He reported the problem ACROS Security, which in turn has notified it Zoom. ACROS Security has also updated its client 0patch, adding a micropatch, closing the vulnerability in four different parts of the code in older versions of Windows.

“Our mikropatchey already released and sent to all connected online applications 0patch Agent. Users Zoom installed 0patch vulnerability are no longer affected,” – said Kolsek.

Here is a video of the exploitation of the vulnerability and a micropatch in action.

Zoom is already working on a fix, but its release date is still unknown. No technical details about the vulnerability ACROS Security not submitted. It is also unclear whether it is exploited in the real attacks.

Previous articleUkraine called the condition of water supply in Crimea
Next articleFound mysterious space objects
Jennifer Alvarez is an investigative journalist and is a correspondent for European Union. She is based in Zurich in Switzerland and her field of work include covering human rights violations which take place in the various countries in and outside Europe. She also reports about the political situation in European Union. She has worked with some reputed companies in Europe and is currently contributing to USA News as a freelance journalist. As someone who has a Masters’ degree in Human Rights she also delivers lectures on Intercultural Management to students of Human Rights. She is also an authority on the Arab world politics and their diversity.