Zoom Patches “Zero-Click” RCE Bug

Published on 31 May 2022
1 min read
Vulnerability

A medium-severity vulnerability found by Google Project Zero researcher Ivan Fratric and named as “XMPP stanza smuggling” has been patched by Zoom. It has a CVSS severity rating of 5.9 and is tracked as

CVE-2022-22787.

It affects the majority of operating systems, including Windows, macOS, iOS, and Android users. Zoom has urged us to update its client software to the latest 5.10.0 version.

Being a zero-click vulnerability, even without any action from a user, the vulnerability can be exploited.

Even the highly tech-aware users can fall prey to them.

All it is required for the attacker is to be able to send messages to the victim over the Zoom chat with the XMPP (Extensible Messaging Presence Protocol). XMPP is used to send XML elements between 2 connections. It is used to exchange messages and the presence information (whether they are online or not) in real-time, which is implemented in Zoom chat functionality.

Also, Zoom stated in its security bulletin, that the earlier version fails “to properly validate the hostname during a server switch request.”

The vulnerability can be utilized for numerous evil purposes - ranging from spoofing the messages to make them seem to originate from a different user to send control messages to make them seem to come from the server.

It can even allow the bad actor to exploit the ClusterSwitch.

For the POC, Fratric replaced the Zoom’s web server’s domain with another server he controlled, which in turn enabled him to see the traffic flow between the client and the Zoom web server.

He also stated that, “This, in turn, allowed me to MITM the client update process and escalate to arbitrary code execution.”

In order to mitigate the threat, just make sure you have updated your Zoom to the latest version (5.10.0).

Deepraj R
Written by
Content Specialist

Deepraj's content stands as a testament to his ability to transform ideas into compelling stories, making even the most complex subjects accessible to a diverse audience. With a sharp eye for detail and a flair for storytelling, he is a driving force in the world of content creation, connecting businesses and readers through the magic of words.

Nash N Sulthan
Reviewed by
Cyber Security Lead Engineer

Nash is a seasoned Security Engineer who brings a multifaceted approach to safeguarding digital environments. Not only does he excel in implementing robust security measures, but he's also deeply involved in the research and development process, constantly innovating to stay ahead of cyber threats. Nash's commitment to security extends beyond the conventional, making him a valuable contributor to the evolving landscape of digital defense.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo