Open SSL vulnerability - version lower than 3.1.5

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2024-02-14 03:06 AM
Hi,
The previous thread https://community.zoom.com/t5/Meetings/OpenSSL-Vulnerability-Zoom-Meetings-uses-old-version-3-1-1/m-... has been marked as closed.
Please advise if there is an updated Zoom installer version available that includes OpenSSL version 3.1.5 or above?
Please would you let us have an eta?
- Topics:
-
Meeting Features
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2024-02-23 08:10 AM - edited 2024-02-23 08:11 AM
@PaulB10000 The latest Zoom client utilizes security fixes addressed in OpenSSL 3.1.5 and is packaged with version 3.1.4. Since Microsoft Defender only detects OpenSSL 3.1.4 and not our custom fix, it outputs a warning. Once OpenSSL 3.1.5 is available as a stable release, Zoom plans to adopt this version into the Zoom apps and that change will be called out in our official release notes. Many thanks to @Bort for researching this internally.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2024-07-10 11:50 AM
Virginia, thank you for the info--knowing you have a custom patch in place provides some peace of mind.
And 3.1.5 has been stable for months, 3.1.6 is now stable for over a month. Zoom has done major updates, moving us all to your workplace. But if it continues to be months to years behind (this issue has been around that long, going back in my experience to at least 3.1), I'm going to have to remove Zoom from all our client systems. It simply represents too much custom work for our security folks to constantly make exceptions for your software.
Is there any plan to actually address this?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2024-05-07 07:23 AM
Hi @VA Has there been any update on this one?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2024-05-08 11:33 AM
