Software Development

Zoom patches conference software after Tenable discovers security vulnerability

The flaw could've allowed an attacker to hijack a meeting, according to Columbia-based Tenable.

A screenshot from Tenable's video on the Zoom vulnerability. (Courtesy photo)

Tenable was behind one software update to fix security flaws that’s circulating this week.
The research arm of the Columbia-based cybersecurity company discovered a vulnerability in Zoom’s conferencing platform that would allow attackers to take control of a user’s desktop remotely during a meeting.
After being alerted, Tenable said that Zoom quickly updated the software.
According to Tenable, the security flaw, if exploited, would allow attackers to do the following:

  • Hijack control of a screen, allowing them to download and execute malware.
  • Impersonate others in the meeting through chat messages.
  • Kick out other attendees of the meeting.

A blog post from the company states the vulnerability was discovered by Tenable’s David Wells.
“This impacts both one-on-one (P2P) meetings as well as group meetings streamed through Zoom servers,” the blog post states, adding that the vulnerability could also be exploited over Wide Area Network (WAN).
The vulnerability could’ve put 750,000 companies that use Zoom at risk.
To fix the vulnerability, Zoom patched servers and released new versions of the software. The company is urging users to ensure their software is up-to-date.
This vulnerability is the perfect example of the cyber attack surface that is expanded by seemingly innocuous services, like Zoom,” Tenable CTO Renaud Deraison said in a statement.
In September, the recently IPO’d company released research on a vulnerability in security cameras used around the world.

Companies: Tenable Holdings

Before you go...

Please consider supporting Technical.ly to keep our independent journalism strong. Unlike most business-focused media outlets, we don’t have a paywall. Instead, we count on your personal and organizational support.

3 ways to support our work:
  • Contribute to the Journalism Fund. Charitable giving ensures our information remains free and accessible for residents to discover workforce programs and entrepreneurship pathways. This includes philanthropic grants and individual tax-deductible donations from readers like you.
  • Use our Preferred Partners. Our directory of vetted providers offers high-quality recommendations for services our readers need, and each referral supports our journalism.
  • Use our services. If you need entrepreneurs and tech leaders to buy your services, are seeking technologists to hire or want more professionals to know about your ecosystem, Technical.ly has the biggest and most engaged audience in the mid-Atlantic. We help companies tell their stories and answer big questions to meet and serve our community.
The journalism fund Preferred partners Our services
Engagement

Join our growing Slack community

Join 5,000 tech professionals and entrepreneurs in our community Slack today!

Trending

What a second Trump administration means for local startup ecosystems

The metrics and mechanics that get startups funded, according to 5 active investors

How hackathon winner ‘Curious GeorgePT' works to reduce AI bias

This Week in Jobs: 31 open roles to cure the common career

Technically Media