SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Conferencing Application Zoom Allows Remote Activation of Your Mic and Cam Without Questions
Date    Wednesday July 10 2019, @11:47AM
Author    chromas
Topic   
from the Now-you-see-me-now-you-still-do dept.
https://soylentnews.org/article.pl?sid=19/07/10/1053229

pkrasimirov writes:

InfoSec Write-ups:

A vulnerability in the Mac Zoom Client allows any malicious website to enable your camera without your permission. The flaw potentially exposes up to 750,000 companies around the world that use Zoom to conduct day-to-day business.

[...] This vulnerability allows any website to forcibly join a user to a Zoom call, with their video camera activated, without the user's permission.

On top of this, this vulnerability would have allowed any webpage to DOS (Denial of Service) a Mac by repeatedly joining a user to an invalid call.

Additionally, if you've ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you, without requiring any user interaction on your behalf besides visiting a webpage. This re-install 'feature' continues to work to this day.

[...] According to Zoom, they will have a fix shipped by midnight tonight pacific time removing the hidden web server; hopefully this patches the most glaring parts of this vulnerability. The Zoom CEO has also assured us that they will be updating their application to further protect users privacy.

Proof of concept:
https://jlleitschuh.org/zoom_vulnerability_poc/zoompwn_iframe.html
WARNING: Clicking this link starts a Zoom video call, no questions asked!


Original Submission

Links

  1. "pkrasimirov" - https://soylentnews.org/~pkrasimirov/
  2. "InfoSec Write-ups" - https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=34948

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Conferencing Application Zoom Allows Remote Activation of Your Mic and Cam Without Questions on 2024-04-25 02:25:44