Zoom Structural Vulnerability Discovered

Adeel Sadiq 11beeasadiq at SEECS.EDU.PK
Tue Jul 9 16:07:42 EEST 2019


Speaking from a technical perspective, no software is perfect or bug-free.
Its only a matter of time a loophole is found and exploited and eventually
patched up. If you think Adobe Connect or ezTalks were/are free of these
architectural issues, think again! That's the way we technical community do
things.

Regards

Adeel
Pakistan

On Wed, Jul 10, 2019 at 1:37 AM Ayden Férdeline <icann at ferdeline.com> wrote:

> Unfortunately, uninstalling the application does not rectify the
> situation, due to poor architecture (acknowledged by Zoom on their blog
> today). They are working on a fix, now that public scrutiny demands one. So
> disappointing that ICANN has put us in this terrible situation.
>
> Ayden
>
>
> On Tue, Jul 9, 2019 at 16:15, Vaibhav Aggarwal, Catalyst & Group CEO <
> va at BLADEBRAINS.COM> wrote:
>
> Thanks for this. Till the next Update, I have removed the Zoom For Mac
> Client with immediate effect.
>
> Regards,
> Vaibhav Aggarwal
> New Delhi
> VaibhavAggarwal.com
>
>
> On Jul 10, 2019, at 12:30 AM, Michael Karanicolas <mkaranicolas at GMAIL.COM>
> wrote:
>
> Hey - remember when ICANN switched everyone from Adobe over to Zoom as a
> way of enhancing information security and data privacy?
>
> "A vulnerability in the Mac Zoom Client allows any malicious website to
> enable your camera without your permission... This vulnerability allows any
> website to forcibly join a user to a Zoom call, with their video camera
> activated, without the user's permission. On top of this, this
> vulnerability would have allowed any webpage to DOS (Denial of Service) a
> Mac by repeatedly joining a user to an invalid call. Additionally, if
> you’ve ever installed the Zoom client and then uninstalled it, you still
> have a localhost web server on your machine that will happily re-install
> the Zoom client for you, without requiring any user interaction on your
> behalf besides visiting a webpage. This re-install ‘feature’ continues to
> work to this day."
>
> Read more here:
> https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
>
>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190709/c5feec18/attachment.htm>


More information about the Ncsg-discuss mailing list