Comprehensive software reviews to make better IT decisions
Two New Zoom Vulnerabilities Uncovered – Upgrade Now!
Two new vulnerabilities in Zoom’s web conferencing software were discovered in early June 2020. These vulnerabilities could allow malicious actors the ability to execute arbitrary code on target hosts and exploit path traversal vulnerabilities in the software. Zoom’s latest update addresses and remediates the vulnerabilities.
Path Traversal attacks enable access to files and directories outside of a web root folder, which would allow a malicious actor to access files stored on a system that were not meant to be publicly available to the web application.
The vulnerabilities were uncovered by Cisco Talos and are listed under Common Vulnerabilities and Exposures (CVE) ID numbers CVE-2020-6109 and CVE-2020-6110. CVE-2020-6109 affects GIPHY, the messaging and animated GIF application. CVE-2020-6110 exploits a chat code snippet in Zoom.
The vulnerabilities are found in version 4.6 of Zoom, one of which “impacts Zoom 4.6.10, 4.6.11 and likely earlier versions, [while the other] only affects 4.6.10 and earlier.”, according to Security Week.
Source: SoftwareReviews. Accessed June 9, 2020
Both vulnerabilities have been addressed in Zoom’s 5.0 update, released in May 2020. Zoom has addressed the vulnerabilities on both the server and client; software on client workstations will need to be upgraded manually.
Upgrade your end-user workstations to the latest Zoom software! The patches released by Zoom address issues on the client software distributed and installed on user workstations. Therefore, IT departments are strongly encouraged to roll out the patch as soon as possible and ensure that all users comply with direction to upgrade their software.
Systems administrators can either distribute the update via your organization’s software distribution tools or have end users execute the upgrade on their own. As a standard practice, we recommend conducing a risk assessment of all software patches to identify urgency and to schedule their installation or deployment accordingly.
Stay tuned to Info-Tech’s Tech Briefs; we will report on developments as they transpire.
This note outlines Info-Tech’s Three C’s of Enterprise Collaboration framework to help buyers effectively navigate the collaboration software marketspace.
With a return to the office looking ever more feasible, organizations need to consider what role web conferencing solutions will play moving forward. This note outlines three trends organizations should be aware of as we move into 2022.
On March 11, 2021, Verizon provided updates to BlueJeans’ product vision and direction for FY2021. BlueJeans experienced dramatic adoption in 2020, particularly for webinars and events, and seeks to offer advanced breakout room features in the future.
On February 24-25, 2021, Zoho held its annual ZohoDay – a conference aimed at communicating the state of the business and product roadmaps. The event coincided with Zoho’s 25th year as a company, testament to Zoho’s long-term business approach: grow organically, have zero debt, zero external investments, remain cashflow positive, and plow cashflow back into the business and customers.
On October 29, 2020, Verizon briefed on BlueJeans’ product vision and direction. This note outlines the new and upcoming features that users can expect from BlueJeans for the rest of 2020 and into 2021. However, with the table stakes margin for features rapidly increasing in the web conferencing marketspace, BlueJeans’ new features are less a way to stand out from the crowd and more as a necessity to keep up.
On November 5, 2020, Cisco briefed on its upcoming virtual legislative session tool Webex Legislate. With a range of features that governing bodies around the globe have desired throughout the extent of the pandemic, Webex Legislate surely becomes the must-have tool for conducting virtual and hybrid sessions – especially if an agency is already leveraging Cisco products.
On September 1, 2020, Info-Tech briefed with Cisco about current and upcoming features of its Unified Webex app for September. Significant changes include the introduction of Cisco Webex Classrooms and the Webex Control Hub, with notable updates also coming to Webex for Education, Webex Meetings, and Webex Teams.
On September 4, 2020, Info-Tech briefed with Zoho about current and upcoming features of Zoho Workplace, a global enterprise collaboration platform. Organizations, especially SMBs, that want to look outside of Microsoft’s and Google’s office productivity suite duopoly should consider shortlisting Zoho Workplace as a viable option.
Enterprise Connect’s virtual conference and expo for 2020 featured a wide variety of sessions on communications and collaboration for the enterprise. In this fourteenth note of fourteen, I report on Recon Research’s latest study on how COVID-19 has cemented web conferencing as the future of the workplace.