Zoom Structural Vulnerability Discovered
Ayden Férdeline
icann at FERDELINE.COM
Tue Jul 9 15:35:48 EEST 2019
Unfortunately, uninstalling the application does not rectify the situation, due to poor architecture (acknowledged by Zoom on their blog today). They are working on a fix, now that public scrutiny demands one. So disappointing that ICANN has put us in this terrible situation.
Ayden
On Tue, Jul 9, 2019 at 16:15, Vaibhav Aggarwal, Catalyst & Group CEO <va at BLADEBRAINS.COM> wrote:
> Thanks for this. Till the next Update, I have removed the Zoom For Mac Client with immediate effect.
>
> Regards,
> Vaibhav Aggarwal
> New Delhi
> VaibhavAggarwal.com
>
>> On Jul 10, 2019, at 12:30 AM, Michael Karanicolas <mkaranicolas at GMAIL.COM> wrote:
>>
>> Hey - remember when ICANN switched everyone from Adobe over to Zoom as a way of enhancing information security and data privacy?
>>
>> "A vulnerability in the Mac Zoom Client allows any malicious website to enable your camera without your permission... This vulnerability allows any website to forcibly join a user to a Zoom call, with their video camera activated, without the user's permission. On top of this, this vulnerability would have allowed any webpage to DOS (Denial of Service) a Mac by repeatedly joining a user to an invalid call. Additionally, if you’ve ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you, without requiring any user interaction on your behalf besides visiting a webpage. This re-install ‘feature’ continues to work to this day."
>>
>> Read more here: https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190709/705e950a/attachment.htm>
More information about the Ncsg-discuss
mailing list