Critical Bug Fixed in VINTEO Video Conferencing System

📟 News

Date: 25/07/2025

A critical RCE vulnerability has been fixed in the Russian video conferencing system VINTEO. The issue was caused by a feature in the implementation of a component that had insufficient filtering of user data.

The VINTEO video conferencing server is designed for building new VCS infrastructure and scaling existing networks. According to the manufacturer, VINTEO solutions have facilitated approximately 10 million video conferences over the past 12 years.

The issue was assigned the identifier BDU:2025-07296 (9.3 points on the CVSS scale) and was discovered in January 2025 by Positive Technologies specialists Mikhail Klyuchnikov and Alexander Starikov during a code analysis of the software on a test environment provided by VINTEO for research purposes.

It has been reported that the manufacturer was notified of the threat and promptly released a patch for their clients, completely resolving the issue. Subsequently, a comprehensive software update with the fix was prepared.

“In the event of a successful exploitation of the vulnerability, a potential attacker could execute arbitrary commands and gain access to the server and control over it. Subsequent attack scenarios could vary greatly,” comments Mikhail Klyuchnikov, Head of the Software Research Group in the Penetration Testing Department at Positive Technologies.

A vulnerability fixed in the new release was present in VINTEO 30.0.0, and users are now advised to install version 30.2.0 or newer as soon as possible.

Related posts:
2025.01.29 — Google to disable Sync in older Chrome versions

Google announced that in early 2025, Chrome Sync will be disabled in Chrome versions older than four years. Chrome Sync enables users to save and sync their…

Full article →
2025.04.29 — FBI Offers 10 million USD for information on Salt Typhoon members

The FBI offers up to 10 million USD for information about members of the Chinese hacker group Salt Typhoon and last year's attack that had…

Full article →
2025.02.23 — New JavaScript obfuscation technique uses invisible Unicode characters

According to Juniper Threat Labs , a new JavaScript obfuscation technique that uses invisible Unicode characters was used in a phishing attack targeting Political Action…

Full article →
2025.03.10 — Nearly a million Windows computers impacted by a malvertising campaign

According to Microsoft, nearly 1 million Windows devices fell victim to a sophisticated malvertising campaign in recent months. Cybercriminals were able to steal credentials, cryptocurrency, and sensitive…

Full article →
2025.02.06 — Let's Encrypt to stop sending expiration notification emails

The nonprofit organization announced that, starting June 4, 2025, it will stop sending expiration notification emails to subscribers. The primary reason behind this decision…

Full article →
2025.04.30 — Coinbase fixes 2FA bug that made customers panic

Cryptocurrency exchange Coinbase has fixed a bug in its Account Activity logs that caused customers to think their credentials were compromised. Earlier this month, BleepingComputer…

Full article →
2025.02.28 — Qualcomm extends support for Android devices to 8 years

Qualcomm Technologies announced its collaboration with Google with the purpose to provide extended support for OEM devices running on company's flagship chipsets. This partnership will…

Full article →
2025.01.26 — Cisco patched a critical vulnerability in Meeting Management

Cisco released updates to fix a critical (CVSS score: 9.9) vulnerability in Meeting Management. The bug enables an unprivileged remote authenticated attacker to gain administrative privileges. The vulnerability…

Full article →
2025.02.08 — Hackers exploit RCE vulnerability in Microsoft Outlook

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Federal Civilian Executive Branch (FCEB) Agencies that they have to secure their systems from ongoing…

Full article →
2025.03.16 — Researchers force DeepSeek to write malware

According to Tenable, the AI chatbot DeepSeek R1 from China can be used to write malware (e.g. keyloggers and ransomware). DeepSeek was released in January 2025 and caused a stir…

Full article →