QID 379379
Date Published: 2024-03-04
QID 379379: Zoom Clients Business Logic Error Information Disclosure Vulnerability (ZSB-24006)
Business logic error with in-meeting chat for some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
Zoom has released a security update for zoom to fix the vulnerabilities.
Affected Versions:
Zoom Desktop Client for Windows before version 5.16.5
Zoom Desktop Client for macOS before version 5.16.5
Zoom Desktop Client for Linux before version 5.16.5
Zoom VDI Client for Windows before version 5.17.5 (excluding 5.15.15 and 5.16.10)
Zoom Rooms Clients before version 5.17.0 (Windows and MacOSX)
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom products using registry entry for windows and firing commands in linux and macosx.
Successful exploitation of this vulnerability could lead to a disclosure of sensitive information.
CVEs related to QID 379379
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-24006 |
|