Rewterz Threat Advisory – Multiple NETGEAR Devices Vulnerabilities
March 17, 2023Rewterz Threat Alert – SideWinder APT Group – Active IOCs
March 17, 2023Rewterz Threat Advisory – Multiple NETGEAR Devices Vulnerabilities
March 17, 2023Rewterz Threat Alert – SideWinder APT Group – Active IOCs
March 17, 2023Severity
High
Analysis Summary
CVE-2023-22882 CVSS:7.7
Zoom is vulnerable to a denial of service, caused by a STUN parsing vulnerability. By sending specially crafted UDP traffic, a remote authenticated attacker could exploit this vulnerability to cause the application to crash.
CVE-2023-22885 CVSS:9.6
Zoom Clients could allow a remote attacker to execute arbitrary code on the system, caused by improper trust boundary implementation for SMB. By sending a specially crafted request, an attacker could exploit this vulnerability to gain access to a user’s device and data, and remote code execution.
CVE-2023-22883 CVSS:7.2
Zoom Client for Meetings for IT Admin Windows installers could allow a local authenticated attacker to gain elevated privileges on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate their privileges to the SYSTEM user.
CVE-2023-22881 CVSS:6.5
Zoom is vulnerable to a denial of service, caused by a STUN parsing vulnerability. By sending specially crafted UDP traffic, a remote authenticated attacker could exploit this vulnerability to cause the application to crash.
CVE-2023-22880 CVSS:6.8
Zoom for Windows clients could allow a remote authenticated attacker to obtain sensitive information. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information.
Impact
- Denial of Service
- Privilege Escalation
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-22882
- CVE-2023-22885
- CVE-2023-22883
- CVE-2023-22881
- CVE-2023-22880
Affected Vendors
Zoom
Affected Products
- Zoom (for Android
- iOS
- Linux
- macOS
- and Windows) clients 5.13.4
- Zoom VDI Windows Meeting clients 5.13.9
- Zoom for Windows clients 5.13.2
- Zoom Rooms for Windows clients 5.13.2
- Zoom VDI for Windows clients 5.13
Remediation
Refer to Zoom Security Bulletin for patch, upgrade or suggested workaround information.