Skip to content

Latest ZAC Version 9.2 – Now Available for All Zultys Deployments  Download Update Now

Connect With an Expert: 888-985-8971

Connect With an Expert: 888-985-8971

  • Contact Zultys Support
  • Get a Quote
  • Login
    • Customer Billing
  • Contact Zultys Support
  • Get a Quote
  • Login
    • Customer Billing
Zultys logo
  • Products

    Unified Communications

    • ZAC
    • Mobile ZAC

    Integrated Contact Center

    Business Phone Systems

    • Zultys Cloud Services
    • On-Premise and Virtual
    • Hardware as a Service

    Application Integration

    Phones and Accessories

    • ZIP 49GA IP Phone
    • ZIP 47GE IP Phone
    • ZIP 45G IP Phone
    • Z 23GE IP Phone
    • Z 22G IP Phone
    • Z 21i IP Phone
    • Gateways

    FEATURED PRODUCT

    Integrated Contact Center

    Optimize operations, efficiently manage high call volume, increase customer engagement, and improve the customer service experience.

    Contact representative on the phone with a customer
    Learn More
  • Solutions

    Industry

    • Healthcare
    • Education
    • Professional Services & Tech
    • Real Estate
    • Retail & Automotive

    Business Type

    • Small Business
    • Multi-Location
    • Enterprise

    FEATURED

    Zultys Case Studies and Videos

    Get insight into our Partner and customer community and their experiences using the Zultys UC solution.

    Learn More
    Person accessing Zultys case studies through mobile and laptop
  • Resources

    Product Resources

    • Videos & Tutorials
    • User Manuals
    • FAQs
    • ZCS Service Status
    • Product Flyers & Brochures

    Company Resources

    • Case Studies
    • News & Blog
    • Technologies We Work With

    FEATURED

    Zultys MX System Release 18.2 & ZAC 9.2

    Make sure you’re getting all Zultys has to offer by updating to the latest version.
    Learn More
    Person updating computer to latest version
  • Partner With Us
  • Contact Zultys Support – Zultys
  • Get a Quote
  • Request Demo
  • Customer Billing
Request Demo

SAN23-002

Zultys Security Advisory Notice - SAN23-002 Rev 1.1

Webp Vulnerability - Impact on Zultys UC Clients (CVE-2023-4863)

Severity: High
Published: 2023-10-18
Updated: 2023-10-30
Revision: 1.1

Impacted Products

ZAC
WebZAC – depends on the web browser used
MX Mobile for iPhone – depends on operating system
Zultys Mobile for Android – depends on operating system

Affected Releases

ZAC – up to and including version 8.4.32
WebZAC – vulnerability depends on the web browser used
MX Mobile (iOS) – vulnerability depends on the underlying iOS operating system
Zultys Mobile for Android – vulnerability depends on the underlying Android operating system

Products Not Impacted

MX-SE, MX-SE II, MX-E, MX-Virtual systems

Introduction

A significant vulnerability in the Webp image processing library has been reported by Google (CVE-2023-4863).

The related ‘libwebp’ software is a third-party library used in many software applications including the ZAC client, web browsers such as Google Chrome, Mozilla Firefox and Microsoft Edge, Apple iOS and Android operating systems.

Resolution

ZAC – Zultys has released an updated version of ZAC (8.4.33) which includes an updated libwebp version that resolves the vulnerability reported in CVE-2023-4863. For optimal security, Zultys recommends customers upgrade to the latest ZAC version. The latest ZAC version may be downloaded from https://www.zultys.com/zac or the KBS (https://kbs.zultys.com).

WebZAC – Exposure to vulnerability is dependent on the underlying web browser being used. Update web browser to a version containing a fix for CVE-2023-4863, refer to your web browser vendor for additional information.

MX Mobile for iPhone – Exposure to vulnerability is dependent on the underlying Apple operating system. Update iPhone to a version containing a fix for CVE-2023-4863, refer to phone vendor for additional information.

Zultys Mobile for Android – Exposure to vulnerability is dependent on the underlying Android operating system. Update Android device to a version containing a fix for CVE-2023-4863, refer to phone vendor for additional information.

Customers should ensure that they use an updated web browser incorporating a fix for CVE-2023-4863 to access all web applications.

Additional Information

For ZAC, the softphone in version 8.0.x and later is compatible with MX Release 16.0.4 and later (Release 16.0.4 requires a patch incorporating improvement MX-5313). Customers upgrading from a ZAC version prior to 8.0.x to 8.4.33 that utilize the softphone, must ensure the MX system is running version 16.0.4 or later and the networking requirements detailed in the ZAC 8.4 User Manual are met.

Mitigation/Workaround

For cases where it is not feasible to immediately upgrade to ZAC 8.4.33, support for Webp format images may be disabled in ZAC 8.4.32 and earlier by deleting (or renaming) the ‘qweb.dll’ file located in the ‘imageformats’ folder of the ZAC installation folder. On a Windows PC this will generally be C:\Program Files (x86)\Zultys\ZAC\imageformats.

Change Log

Revision Date Changes
1.0
2023-10-18
Initial Security Advisory Notice.
1.1
2023-10-30
Updates to formatting of advisory.

KBS

This SAN is also available via KBS (https://kbs.zultys.com) FAQ issue ID ‘fq-5175’

Contact

If additional information is required contact support@zultys.com or your Authorized Zultys Channel Partner.

Download PDF
Back to Security Advisories >

Get started with smarter communications today.

Request Demo
Request Quote
Zultys logo

Products

  • Unified Communications
  • ZAC
  • Mobility
  • Integrated Contact Center
  • Phones and Accessories

Platforms

  • Zultys Cloud Services
  • On-Premise and Virtual

Resources

  • Videos & Tutorials
  • User Manuals
  • FAQs
  • ZCS Service Status
  • Speedtest
  • Product Flyers & Brochures
  • Case Studies

Company

  • About Us
  • News & Blog
  • Careers
  • Contact Us
Linkedin Facebook-f Twitter
Linkedin Facebook-f Twitter Youtube

Copyright ©2006 – 2025 Zultys, Inc. All Rights Reserved

Legal | Privacy​ | Cookie Policy​ | Sitemap
Website Terms and Conditions | Privacy Policy​ | Legal | Sitemap
You’ll get a reply shortly. We typically reply in a few minutes

Connecting with agent...

Please introduce yourself and post your question to start live chat


By engaging in this chat, you hereby grant consent for Zultys to use and retain the content of this conversation.

Thank you for chatting with us. We are always happy to help you!

Are you sure you want to leave the chat? Connection with the agent will be lost