Zoom Structural Vulnerability Discovered
Vaibhav Aggarwal, Catalyst & Group CEO
va at BLADEBRAINS.COM
Tue Jul 9 14:15:45 EEST 2019
Thanks for this. Till the next Update, I have removed the Zoom For Mac Client with immediate effect.
Regards,
Vaibhav Aggarwal
New Delhi
VaibhavAggarwal.com <http://vaibhavaggarwal.com/>
> On Jul 10, 2019, at 12:30 AM, Michael Karanicolas <mkaranicolas at GMAIL.COM> wrote:
>
> Hey - remember when ICANN switched everyone from Adobe over to Zoom as a way of enhancing information security and data privacy?
>
> "A vulnerability in the Mac Zoom Client allows any malicious website to enable your camera without your permission... This vulnerability allows any website to forcibly join a user to a Zoom call, with their video camera activated, without the user's permission. On top of this, this vulnerability would have allowed any webpage to DOS (Denial of Service) a Mac by repeatedly joining a user to an invalid call. Additionally, if you’ve ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you, without requiring any user interaction on your behalf besides visiting a webpage. This re-install ‘feature’ continues to work to this day."
>
> Read more here: https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5 <https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190709/79460e6a/attachment.htm>
More information about the Ncsg-discuss
mailing list