Security News > 2020 > July > Zoom Working on Patch for Code Execution Vulnerability in Windows Client
Zoom is working on resolving a remote code execution vulnerability affecting the Windows client, but a third-party fix has been made available for users who don't want to wait for the official patch.
On Thursday, ACROS Security announced the availability of a micro-patch for a remote code execution vulnerability in Zoom Client for Windows.
0patch's security researchers released a micropatch that removes the vulnerability in four different areas of the code, and ported the fix from Zoom Client for Windows 5.1.2 to the previous five versions of the application, back to 5.0.3.
0patch, which published a video showing the vulnerability being exploited in an attack, notes that Windows 10 and Windows 8 machines are not affected.
"Zoom takes all reports of potential security vulnerabilities seriously. Yesterday morning we received a report of an issue impacting users running Windows 7 and older. We have confirmed this issue and are currently working on a patch to quickly resolve it," a Zoom spokesperson said, responding to a SecurityWeek inquiry.
News URL
Related news
- Patching problems: The “return” of a Windows Themes spoofing vulnerability (source)
- Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems (source)
- PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs and Patch Released (source)
- Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console (source)
- Microsoft says premature patch could make Windows Recall forget how to work (source)
- New Windows zero-day exposes NTLM credentials, gets unofficial patch (source)
- Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged (source)
- Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability (source)
- Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others (source)
- BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products (source)