- Get link
- X
- Other Apps
- Get link
- X
- Other Apps
Researcher called Matthew Hickey from the company found this vulnerability. The vulnerability was reported to zoom.
Anyone can add malicious links to chat like to expose computer name or domain or windows hashed password. These links can have Microsoft Excel, which can execute the malicious code when opened. Once anyone has your hash password it’s not very difficult to hack the network or other server. This also allows creating backdoor or run malware on target device.
The researcher showed a proof of concept via running the built in calculator app by sending a link
If you send this link to anyone on zoom chat and if they click, it will open the calculator. Alert box might be displayed by Windows in this case but most for advance attacks that might not be the case.
The flaw affects Zoom’s Windows client only. On Apple’s macOS, the Zoom client doesn’t make the links clickable. But on iOS app the app shared all personal information of user with facebook
- Get link
- X
- Other Apps
Comments
Post a Comment