SB2020030604 - Insufficient Session Expiration in Zoom administrator portal



SB2020030604 - Insufficient Session Expiration in Zoom administrator portal

Published: March 6, 2020

Security Bulletin ID SB2020030604
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient Session Expiration (CVE-ID: N/A)

The vulnerability allows a remote user to gain access to target system.

The vulnerability exists due to insufficient session expiration issue in Zoom Conference Room Connector services. A remote administrator with access to the connected device can access the room administration interface, even if this access is revoked by removing the user from the administrator group or by deleting the user altogether.


Remediation

Install update from vendor's website.