QID 376201

Date Published: 2022-01-10

QID 376201: Zoom Client HTML Injection Vulnerability (ZSB-21015)

Zoom Meetings is a proprietary video teleconferencing software program developed by Zoom Video Communications.

The Zoom Client for Meetings for Ubuntu Linux is vulnerable to an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. Affected Versions:
Ubuntu Linux before version 5.1.0

This could allow meeting participants to be targeted for social engineering attacks.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers can update to latest version here

    CVEs related to QID 376201

    Software Advisories
    Advisory ID Software Component Link
    ZSB-21015 URL Logo zoom.us/download