Latest Zoom Update Patches Several Security Vulnerabilities
One of the vulnerabilities patched with this update allowed remote code execution. Sending a specially crafted message enabled a malicious actor to trick Zoom users to connect to a middle server without them noticing any anomaly. The attacker could then launch a more sophisticated attack. They could spoof messages as if incoming from another user. Perhaps they could control all messages coming from the server as well as the client. Identified by Common Vulnerabilities and Exposures (CVE) number CVE-2022-22784, this issue was reported by Google Project Zero security researcher Ivan Fratric....