Zoom Structural Vulnerability Discovered

Michael Karanicolas mkaranicolas at GMAIL.COM
Tue Jul 9 14:00:17 EEST 2019


Hey - remember when ICANN switched everyone from Adobe over to Zoom as a
way of enhancing information security and data privacy?

"A vulnerability in the Mac Zoom Client allows any malicious website to
enable your camera without your permission... This vulnerability allows any
website to forcibly join a user to a Zoom call, with their video camera
activated, without the user's permission. On top of this, this
vulnerability would have allowed any webpage to DOS (Denial of Service) a
Mac by repeatedly joining a user to an invalid call. Additionally, if
you’ve ever installed the Zoom client and then uninstalled it, you still
have a localhost web server on your machine that will happily re-install
the Zoom client for you, without requiring any user interaction on your
behalf besides visiting a webpage. This re-install ‘feature’ continues to
work to this day."

Read more here:
https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190709/625bd110/attachment.htm>


More information about the Ncsg-discuss mailing list