<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">Important Security Update for Zoom on Mac</title>
  <updated>2022-08-24T17:46:07+01:00</updated>
  <generator uri="http://framework.zend.com" version="1.12.20">Zend_Feed_Writer</generator>
  <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085"/>
  <link rel="self" type="application/atom+xml" href="https://www.augwessex.org.uk/discussions/view/2085/feed"/>
  <id>https://www.augwessex.org.uk/discussions/view/2085</id>
  <author>
    <name>AUGW</name>
    <email>info@augwessex.org.uk</email>
    <uri>https://www.augwessex.org.uk/</uri>
  </author>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-15T11:19:57+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10389"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10389</id>
    <author>
      <name>Tony Still</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">There is a serious security vulnerability in the current version of Zoom for Mac. If you have it installed, you should update it soon using the very recent (14th Aug?) update.<xhtml:br/>
<xhtml:br/>
Esteemed Mac security researcher Patrick Wardle reported this last December but Zoom's fix was flawed. He presented it at the Def Con conference last week and a valid fix is now available. Read more <xhtml:a href="https://www.computing.co.uk/news/4054734/zoom-fixes-dangerous-flaw-mac" target="blank">here</xhtml:a>.<xhtml:br/>
<xhtml:br/>
The problem is with Zoom's auto-update that can be tricked into downloading any malware and then escalating its privileges to root (Wardle's slides are <xhtml:a href="https://speakerdeck.com/patrickwardle/youre-muted-rooted" target="blank">here</xhtml:a>). I believe this needs a local (to your Mac) user to trigger it but that could be an innocent (you?) prompted by a social engineering attack (ie they tricked you). The root access grants the malware access to everything.<xhtml:br/>
<xhtml:br/>
Sadly this is not the first serious incident with Zoom on Mac, see <xhtml:a href="https://objective-see.org/blog/blog_0x56.html" target="blank">The 'S' in Zoom, Stands for Security</xhtml:a>.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-17T11:32:53+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10390"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10390</id>
    <author>
      <name>Drew McFarlane</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thank you Tony, have you the latest Version Number (Update) please.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-17T18:34:36+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10391"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10391</id>
    <author>
      <name>Mick Burrell</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">5.11.5</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-17T18:41:33+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10392"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10392</id>
    <author>
      <name>Drew McFarlane</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thank you Mick, I am updated.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-19T21:13:31+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10394"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10394</id>
    <author>
      <name>Andrew Kemp</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">The latest version is now 5.11.6, because the fix in 5.11.5 <xhtml:a href="https://arstechnica.com/information-technology/2022/08/zoom-patches-critical-vulnerability-again-after-prior-fix-was-bypassed/" target="blank">could be bypassed</xhtml:a>.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-22T19:42:04+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10395"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10395</id>
    <author>
      <name>Barrie Turner</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thanks for the Zoom update notice ver.5.11.5 (9788)<xhtml:br/>
<xhtml:br/>
Barrie</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-23T12:23:09+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10396"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10396</id>
    <author>
      <name>Tony Still</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Thanks Andrew for noting that "The latest version is now 5.11.6".<xhtml:br/>
<xhtml:br/>
The ...6 is important because the ...5 version's fix was broken.</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-24T09:36:03+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10397"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10397</id>
    <author>
      <name>Richard I</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">I have just done the update and the latest version is now 5.11.9. So much for a right first time approach!!</xhtml:div>
    </content>
  </entry>
  <entry xmlns:xhtml="http://www.w3.org/1999/xhtml">
    <title type="html"><![CDATA[Re: Important Security Update for Zoom on Mac]]></title>
    <updated>2022-08-24T17:46:07+01:00</updated>
    <link rel="alternate" type="text/html" href="https://www.augwessex.org.uk/discussions/view/2085#10400"/>
    <id>https://www.augwessex.org.uk/discussions/view/2085#10400</id>
    <author>
      <name>Lionel Ogden</name>
      <email>info@augwessex.org.uk</email>
      <uri>https://www.augwessex.org.uk/</uri>
    </author>
    <content xmlns:xhtml="http://www.w3.org/1999/xhtml" type="xhtml">
      <xhtml:div xmlns:xhtml="http://www.w3.org/1999/xhtml">Just did the 5.11.9 update.  Perhaps if I check again in ten minutes there will be another update.</xhtml:div>
    </content>
  </entry>
</feed>
