B
今週中
Zoomの注釈ツールに、会議参加者が他の参加者やプレゼンターのクライアントを乗っ取ることができる脆弱性
📌 一言でいうと
Zoomの注釈ツールに、会議参加者が他の参加者やプレゼンターのクライアントを乗っ取ることができる脆弱性が発見されました。この攻撃は、被害者が会議に参加しているだけで成立し、クリックやダウンロードなどの操作は不要です。すでに修正パッチがリリースされており、Zoom Workplaceなどの各プラットフォームで最新バージョンへの更新が推奨されています。
🔍該当判定
- Zoomの画面共有時に「注釈(アノテーション)」機能を利用している
- Zoom Workplaceのバージョンが 7.1.5 または 7.0.6 より古い
- WindowsでZoom Workplace VDI Clientを利用しており、バージョンが 7.0.11 または 6.6.16 より古い
- Zoom Rooms または Zoom Meeting SDK を利用しており、バージョンが 7.1.0 または 7.1.5 より古い
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Zoom Workplace および関連製品(VDI Client, Zoom Rooms, Meeting SDK)を、指定された最新バージョン(Zoom Workplace 7.1.5 / 7.0.6 以降など)にアップデートしてください。
📧 メール案を見る (社員向け + 管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】Zoomアプリの最新バージョンへの更新のお願い
お疲れさまです。情報システム担当です。
Zoomの機能(注釈ツール)に、悪意のある参加者が他の利用者のPCを操作できてしまう深刻な脆弱性が発見されました。
ご協力をお願いしたいこと:
1. お使いのZoomアプリを起動し、最新バージョンにアップデートしてください。
2. アップデートが完了するまで、不特定多数が参加する会議での注釈機能の利用に注意してください。
対応期限: 本日中
お疲れさまです。情報システム担当です。
Zoomの機能(注釈ツール)に、悪意のある参加者が他の利用者のPCを操作できてしまう深刻な脆弱性が発見されました。
ご協力をお願いしたいこと:
1. お使いのZoomアプリを起動し、最新バージョンにアップデートしてください。
2. アップデートが完了するまで、不特定多数が参加する会議での注釈機能の利用に注意してください。
対応期限: 本日中
Subject: [Action Required] Please Update Your Zoom Client
Hi everyone,
A critical vulnerability has been discovered in Zoom's annotation tool that could allow an attacker to take control of another participant's client.
What you need to do:
1. Open your Zoom application and update it to the latest version immediately.
2. Be cautious when using annotation features in meetings with external participants until the update is complete.
Deadline: End of today
Hi everyone,
A critical vulnerability has been discovered in Zoom's annotation tool that could allow an attacker to take control of another participant's client.
What you need to do:
1. Open your Zoom application and update it to the latest version immediately.
2. Be cautious when using annotation features in meetings with external participants until the update is complete.
Deadline: End of today
件名: 【共有】Zoom 注釈ツールにおけるクライアント乗っ取り脆弱性への対応について
お疲れさまです。Zoomの注釈ツールにおける脆弱性に関する情報共有です。
■ 概要
注釈ツール(画面共有上の描画機能)の欠陥により、会議参加者が他の参加者やプレゼンターのクライアントをリモートで操作できる可能性があります。ユーザーの操作(クリック等)を必要としないゼロクリック攻撃が可能です。
■ 影響範囲
- Zoom Workplace: 7.1.5 および 7.0.6 未満
- Zoom Workplace VDI Client for Windows: 7.0.11 および 6.6.16 未満
- Zoom Rooms / Zoom Meeting SDK: 7.1.0 および 7.1.5 未満
■ 対応手順
1. 社内利用しているZoomクライアントのバージョンを確認し、最新版へ強制アップデートを適用する。
2. SDKを利用した自社開発アプリがある場合、SDKを最新バージョンに更新し再デプロイする。
■ 参考情報
- Zoom 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 即時
お疲れさまです。Zoomの注釈ツールにおける脆弱性に関する情報共有です。
■ 概要
注釈ツール(画面共有上の描画機能)の欠陥により、会議参加者が他の参加者やプレゼンターのクライアントをリモートで操作できる可能性があります。ユーザーの操作(クリック等)を必要としないゼロクリック攻撃が可能です。
■ 影響範囲
- Zoom Workplace: 7.1.5 および 7.0.6 未満
- Zoom Workplace VDI Client for Windows: 7.0.11 および 6.6.16 未満
- Zoom Rooms / Zoom Meeting SDK: 7.1.0 および 7.1.5 未満
■ 対応手順
1. 社内利用しているZoomクライアントのバージョンを確認し、最新版へ強制アップデートを適用する。
2. SDKを利用した自社開発アプリがある場合、SDKを最新バージョンに更新し再デプロイする。
■ 参考情報
- Zoom 公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 即時
Subject: [Security Advisory] Zoom Annotation Tool Client Hijacking Vulnerability
Hi team,
This is a technical alert regarding vulnerabilities in Zoom's annotation tool.
■ Overview
Flaws in the annotation feature allow a meeting participant to hijack the client of other attendees or the presenter. This is a zero-click vulnerability requiring no interaction from the victim other than being present in the meeting.
■ Affected Versions
- Zoom Workplace: Before 7.1.5 and 7.0.6
- Zoom Workplace VDI Client for Windows: Before 7.0.11 and 6.6.16
- Zoom Rooms and Zoom Meeting SDK: Before 7.1.0 and 7.1.5
■ Mitigation Steps
1. Ensure all corporate Zoom clients are updated to the latest patched versions.
2. For internal applications using the Zoom Meeting SDK, update the SDK to the latest version and redeploy.
■ Reference
- Zoom Official Security Advisory
Priority: High
Deadline: Immediate
Hi team,
This is a technical alert regarding vulnerabilities in Zoom's annotation tool.
■ Overview
Flaws in the annotation feature allow a meeting participant to hijack the client of other attendees or the presenter. This is a zero-click vulnerability requiring no interaction from the victim other than being present in the meeting.
■ Affected Versions
- Zoom Workplace: Before 7.1.5 and 7.0.6
- Zoom Workplace VDI Client for Windows: Before 7.0.11 and 6.6.16
- Zoom Rooms and Zoom Meeting SDK: Before 7.1.0 and 7.1.5
■ Mitigation Steps
1. Ensure all corporate Zoom clients are updated to the latest patched versions.
2. For internal applications using the Zoom Meeting SDK, update the SDK to the latest version and redeploy.
■ Reference
- Zoom Official Security Advisory
Priority: High
Deadline: Immediate