Zoom Structural Vulnerability Discovered

Remmy Nweke remmyn at GMAIL.COM
Mon Jul 8 12:59:10 EEST 2019


thanks for sharing
____
REMMY NWEKE, mNGE,
Lead Consulting Strategist/Group Executive Editor,
DigitalSENSE Africa Media [*Multiple-award winning medium*]
(DigitalSENSE Business News
<http://www.digitalsenseafrica.com.ng/businessnews>; ITREALMS
<http://www.itrealms.com.ng>, NaijaAgroNet <http://www.naijaagronet.com.ng>)
Block F1, Shop 133 Moyosore Aboderin Plaza, Bolade Junction, Oshodi-Lagos
M: 234-8033592762, 8023122558, 8051000475, T: @ITRealms
<http://www.twitter.com/ITRealms>
Author: A Decade of ICT Reportage in Nigeria
<https://www.facebook.com/adecadeofictreportageinnigeria%E2%80%8E>

*2020 Nigeria DigitalSENSE Forum on IG4D & Nigeria IPv6 Roundtable
<http://www.digitalsenseafrica.com.ng>*
JOIN us!!

*Vice President, African Civil Society on the Information Society (ACSIS
<http://www.acsis-scasi.org/en/>)
_________________________________________________________________
*Confidentiality Notice:* The information in this document and attachments
are confidential and may also be privileged information. It is intended
only for the use of the named recipient. Remmy Nweke does not accept legal
responsibility for the contents of this e-mail. If you are not the intended
recipient, please notify me immediately, then delete this document and do
not disclose the contents of this document to any other person, nor make
any copies. Violators may face court persecution.



On Tue, Jul 9, 2019 at 8:23 PM Johan Helsingius <julf at julf.com> wrote:

> The web client, as well as the Windows, Linux and Android clients
> see OK based on what we know so far.
>
>         Julf
>
> On 09-07-19 21:15, Vaibhav Aggarwal, Catalyst & Group CEO wrote:
> > Thanks for this. Till the next Update, I have removed the Zoom For Mac
> > Client with immediate effect.
> >
> > Regards,
> > Vaibhav Aggarwal
> > New Delhi
> > VaibhavAggarwal.com <http://VaibhavAggarwal.com>
> >
> >
> >> On Jul 10, 2019, at 12:30 AM, Michael Karanicolas
> >> <mkaranicolas at GMAIL.COM <mailto:mkaranicolas at GMAIL.COM>> wrote:
> >>
> >> Hey - remember when ICANN switched everyone from Adobe over to Zoom as
> >> a way of enhancing information security and data privacy?
> >>
> >> "A vulnerability in the Mac Zoom Client allows any malicious website
> >> to enable your camera without your permission... This vulnerability
> >> allows any website to forcibly join a user to a Zoom call, with their
> >> video camera activated, without the user's permission. On top of this,
> >> this vulnerability would have allowed any webpage to DOS (Denial of
> >> Service) a Mac by repeatedly joining a user to an invalid call.
> >> Additionally, if you’ve ever installed the Zoom client and then
> >> uninstalled it, you still have a localhost web server on your machine
> >> that will happily re-install the Zoom client for you, without
> >> requiring any user interaction on your behalf besides visiting a
> >> webpage. This re-install ‘feature’ continues to work to this day."
> >>
> >> Read more
> >> here:
> https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
> >
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190708/edd4420a/attachment.htm>


More information about the Ncsg-discuss mailing list