NCSC Netherlands Advisory: Zoom Vulnerabilities Patched (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Dutch NCSC advisory on Zoom vulnerabilities
- TOCTOU race condition leads to privilege escalation
- Input validation flaws allow account takeover
"Dutch NCSC warned of multiple vulnerabilities in Zoom Windows products including Zoom Client, Zoom Rooms, and other Windows components. Issues include a TOCTOU race condition allowing authenticated local privilege escalation, incorrect privilege management in Zoom Rooms, and input validation flaws enabling unauthenticated network-based account takeover."
no comments yet.