Saturday, April 1, 2023
  • Advertise With Us
  • Write For Us
  • Contact Us
  • About Us
  • Editorial Calendar
Download Latest Issue - Free!
The Cyber Express
World Cybercon Middle East
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    3CX

    Global 3CX Telephone App Users at Risk, CEO Blames ‘Upstream Library’

    HACLA Cyber Attack

    Here’s Everything We Know About HACLA Cyber Attack Claimed by LockBit

    Microsoft Bing Search Results

    Microsoft Bing Search Results Altered Through AAD Misconfiguration

    World Data Backup Day

    World Data Backup Day: Are You Doing it Right?

    UK on AI

    UK Government to Go Light on AI Regulation; Musk, Wozniak Call for Six-month Halt on AI

    Spyware Vendor

    Spanish Spyware Vendor’s Product Used to Target UAE Users, Finds Google

    Microsoft Outlook for Windows

    Australia Warns About Microsoft Outlook for Windows Vulnerability

    BMW Potential Data Breach Puts Customers Information At Risk!

    BMW Potential Data Breach Puts Customers Information At Risk!

    Punjab Police Attacked

    Punjab Police Attacked, Hacktivist Group Eagle Cyber Crew Claims Website Security Breach

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    cybersecurity-education-legislation

    North Dakota Approves Computer Science and Cybersecurity Education Legislation for K-12 Grades

    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Insider threat mitigation

    Behavioral Psychology, a Boon for Insider Risk Mitigation

    Safer Internet

    International Safer Internet Day: How Safe Are Our Teenagers Online?

    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    CISA

    13 Specialists to Join Forces with CISA’s Cybersecurity Advisory Committee

    GISEC Global 2023

    GISEC Global 2023: H.E. Dr Mohamed Hamad Al-Kuwaiti Recognized for Outstanding Contributions in Advancing Global Cybersecurity

    GISEC Global 2023

    GISEC Global 2023: Knowledge Sharing, Collaboration Vital to Fend off Cyberattacks, say Experts

    Call & Contact Center Expo 2023 Las Vegas

    Call & Contact Center Expo 2023 Las Vegas

    Former BookMyShow CTO Mahesh Vandi Chalil

    Cyble Appoints Former BookMyShow CTO Mahesh Vandi Chalil as Chief Product and Technology Officer

    GISEC 2023

    GISEC 2023: Microsoft Highlights Zero Trust Approach and Mixed Reality Policing Tools

    GISEC Global 2023

    GISEC Global 2023: ‘Take the Fight to Cyber Attackers’ Urges UAE Cybersecurity Council Paper

    Cyble in Forbes List

    Cyble Recognized by Forbes as One of America’s Best Startup Employers 2023

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • World CyberCon Middle East 2023
    • Endorsed Events
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    3CX

    Global 3CX Telephone App Users at Risk, CEO Blames ‘Upstream Library’

    HACLA Cyber Attack

    Here’s Everything We Know About HACLA Cyber Attack Claimed by LockBit

    Microsoft Bing Search Results

    Microsoft Bing Search Results Altered Through AAD Misconfiguration

    World Data Backup Day

    World Data Backup Day: Are You Doing it Right?

    UK on AI

    UK Government to Go Light on AI Regulation; Musk, Wozniak Call for Six-month Halt on AI

    Spyware Vendor

    Spanish Spyware Vendor’s Product Used to Target UAE Users, Finds Google

    Microsoft Outlook for Windows

    Australia Warns About Microsoft Outlook for Windows Vulnerability

    BMW Potential Data Breach Puts Customers Information At Risk!

    BMW Potential Data Breach Puts Customers Information At Risk!

    Punjab Police Attacked

    Punjab Police Attacked, Hacktivist Group Eagle Cyber Crew Claims Website Security Breach

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    cybersecurity-education-legislation

    North Dakota Approves Computer Science and Cybersecurity Education Legislation for K-12 Grades

    BreachForums

    FBI Arrests BreachForums Operator ‘Pompompurin’, Slaps Cybercrime Charges

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    Insider threat mitigation

    Behavioral Psychology, a Boon for Insider Risk Mitigation

    Safer Internet

    International Safer Internet Day: How Safe Are Our Teenagers Online?

    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    CISA

    13 Specialists to Join Forces with CISA’s Cybersecurity Advisory Committee

    GISEC Global 2023

    GISEC Global 2023: H.E. Dr Mohamed Hamad Al-Kuwaiti Recognized for Outstanding Contributions in Advancing Global Cybersecurity

    GISEC Global 2023

    GISEC Global 2023: Knowledge Sharing, Collaboration Vital to Fend off Cyberattacks, say Experts

    Call & Contact Center Expo 2023 Las Vegas

    Call & Contact Center Expo 2023 Las Vegas

    Former BookMyShow CTO Mahesh Vandi Chalil

    Cyble Appoints Former BookMyShow CTO Mahesh Vandi Chalil as Chief Product and Technology Officer

    GISEC 2023

    GISEC 2023: Microsoft Highlights Zero Trust Approach and Mixed Reality Policing Tools

    GISEC Global 2023

    GISEC Global 2023: ‘Take the Fight to Cyber Attackers’ Urges UAE Cybersecurity Council Paper

    Cyble in Forbes List

    Cyble Recognized by Forbes as One of America’s Best Startup Employers 2023

    Cybersecurity Excellence Awards

    Cybersecurity Excellence Awards: Cyble Rated Fastest Growing Cybersecurity Company

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • World CyberCon Middle East 2023
    • Endorsed Events
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Zoom Detects Vulnerability Giving Full Access to Hackers, Releases Patch

Editorial by Editorial
October 18, 2022
in Firewall Daily
0
Zoom Vulnerability
592
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

Update October 18, 2022: The American video conferencing company, Zoom, has released a new patch for macOS users to mitigate the CVE-2022-28762 vulnerability having a CVSS severity score of 7.3/10. The vulnerability affects the Zoom Client for Meetings, and exclusively exists on macOS versions 5.10.6 and prior to 5.12.0. It allows threat actors to exploit a port misconfiguration. The exploitation can be initiated by third-party members while using the Zoom App Layers API on the Zoom client because the threat actors could use this debugging port to control and exploit the Zoom Apps running in the Zoom client.

Earlier, the communications platform had reported a new vulnerability on its On-Premise Meeting Connector. The On-Premise Meeting Connector or On-prem is a paid tool for Zoom that enables users to host unlimited meetings and leverage additional customizations, personal meeting IDs, and much more.

You might also like

Global 3CX Telephone App Users at Risk, CEO Blames ‘Upstream Library’

Here’s Everything We Know About HACLA Cyber Attack Claimed by LockBit

Microsoft Bing Search Results Altered Through AAD Misconfiguration

The company’s Offensive Security Team recorded the vulnerability in the previous version (4.8.20220815.130) of MRR, which allows threat actors to gain improper control over the meetings.

Zoom On-Premise Meeting Connector vulnerability

On October 11, 2022, Zoom released an update on the vulnerability and marked it on the severity scale as “Medium.” According to the company, the vulnerability allows hackers and threat actors to steal audio and video feed inside a meeting — even though they are not a part of the organization or are not authorized to view the content. The CVE deployment given to the vulnerability is CVE-2022-28761, with a score of 6.5.

The vulnerability can also allow cyber criminals to steal exchanged data and insights from an organization and use it for blackmailing and phishing campaigns.

In response to the vulnerability, Zoom shared a quick method to update the virtual appliance so that the latest patch can be added to the application. Here’s how to mitigate the CVE-2022-28761 vulnerability and possibly update the virtual appliance

Zoom On-Premise Meeting Connector, how to update the latest patch?

Before updating to the latest version, users are requested to make sure they complete the prerequisites for updating the appliance. This includes “A running Meeting Connector or Virtual Room Connector” and “admin access to the server web interface.” Once these two requirements are sorted, here’s how to update a virtual appliance on the web console interface.

  1. Open Google Chrome, Mozilla Firefox, or any other web browser currently installed on your PC.
  2. In the search bar, type https://IPaddress:5480 and hit enter.
  3. Now, sign in with admin credentials.
  4. On the next page, go to the navigation menu and click on Update.
  5. Click ‘Check for Updates.
  6. On the next screen, check if any updates are available.
  7. The appliance will start the download and installation process.
  8. Once installation is complete, the device will automatically restart.
  9. Sign back into the web console to confirm the update.
  10. Finally, to complete the process, click on Dashboard and verify the ‘zctrl’ and ‘MMR’ processes are running.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: On-Premise Meeting ConnectorThe Cyber ExpressThe Cyber Express NewsZoom
Previous Post

World CyberCon India Edition 2022

Next Post

New Variant of Ducktail Infostealer Targets Facebook Accounts

Editorial

Editorial

The Cyber Express is a publication that aims to provide the latest news and analysis about the information security industry. The news comes from a variety of sources and is updated regularly so that readers can stay up to date with the latest happenings in this rapidly growing field.

Related Posts

3CX
Cybersecurity News

Global 3CX Telephone App Users at Risk, CEO Blames ‘Upstream Library’

by Chandu Gopalakrishnan
March 31, 2023
HACLA Cyber Attack
Dark Web News

Here’s Everything We Know About HACLA Cyber Attack Claimed by LockBit

by Ashish Khaitan
March 31, 2023
Microsoft Bing Search Results
Firewall Daily

Microsoft Bing Search Results Altered Through AAD Misconfiguration

by Vishwa Pandagle
March 31, 2023
World Data Backup Day
Firewall Daily

World Data Backup Day: Are You Doing it Right?

by Chandu Gopalakrishnan
March 31, 2023
UK on AI
Cybersecurity News

UK Government to Go Light on AI Regulation; Musk, Wozniak Call for Six-month Halt on AI

by Chandu Gopalakrishnan
March 30, 2023
Next Post
Ducktail Infostealer

New Variant of Ducktail Infostealer Targets Facebook Accounts

Latest Issue is Out. Subscribe Now

Women in Cybersecurity

Download Now

CRIL


Follow Us On Google News

Never miss an update. Subscribe!

* indicates required

Top 10 Cybersecurity Jobs

Categories

About The Cyber Express

The Cyber Express

Cyber Security News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

Follow The Cyber Express

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Sponsorship/Event Partnership: [email protected]

For Conferences related information: [email protected]

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

Tel: (678) 578-8838

Events: +1 (678) 578-4140

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Tel: (678) 578-8838

Events: +1 (678) 578-4140

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Firewall Daily
  • Business News
  • Cyber Essentials
  • Features
  • Cyber Security Magazine
  • Events
    • World CyberCon Middle East 2023
    •  Cyber Security Webinar

© 2022 The Cyber Express (Cyber Security News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.