Resolved! OpenSSL Vulnerability - Zoom Meetings uses old version 3.1.1
I raised this on the dev forum hoping it would have reached the right set of eyes. https://devforum.zoom.us/t/zoom-5-6-10-vulnerabilities-with-openssl-dll-need-version-3-1-5/98806/1 However, following a Search all prior reports of vulnerabilities have been placed within Zoom Community. Using Zoom Meetings Client 5.16.10 (26186) Install source: https://zoom.us/client/5.16.10.26186/ZoomInstallerFull.exe?archType=x64 Detected files Recommended course of action, upgrade to OpenSSL Version 3.1.5 or 3.2.0 Updating to 3.1.4 would still leave CVE-2023-5678 CVE-2023-4807, Fixed in OpenSSL 3.1.3 (Affected since 3.1.0) CVE-2023-5363 , Fixed in OpenSSL 3.1.4 (Affected since 3.1.0) CVE-2023-3817, Fixed in OpenSSL 3.1.2 (Affected since 3.1.0) CVE-2023-5678 , Fixed in OpenSSL 3.1.5 (Affected since 3.1.0)
Microsoft Defender flags as vulnerable for
CVE-2023-4807 CVSS 6.2,
CVE-2023-5363 CVSS 5.9,
CVE-2023-3817 CVSS 3.7,
CVE-2023-5678 CVSS 3.7,
c:\program files\zoom\bin\libcrypto-3-zm.dll
c:\program files\zoom\bin\libssl-3-zm.dll
OpenSSL Version 3.1.1.0
https://www.openssl.org/news/vulnerabilities.html
gitcommit see git openssl org/gitweb/?p=openssl.git;a=commitdiff;h=4bfac4471f53c4f74c8d81020beb938f92d84ca5
gitcommit see git openssl org/gitweb/?p=openssl.git;a=commitdiff;h=5f69f5c65e483928c4b28ed16af6e5742929f1ee
gitcommit see git openssl org/gitweb/?p=openssl.git;a=commitdiff;h=6a1eb62c29db6cb5eec707f9338aee00f44e26f5
gitcommit see git openssl org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6
Show less