A vulnerability in Zoom's Windows client could let attackers steal Windows login credentials of users who click on malicious links in chat messages
The Zoom Windows client is vulnerable to UNC path injection in the client's chat feature that could allow attackers to steal the Windows credentials of users who click on the link.
BleepingComputer Lawrence Abrams
Related Coverage
- Zoom's security and privacy problems are snowballing Business Insider · Charlie Wood
- Zoom is a privacy disaster — chat links can steal your personal info LaptopMag · Phillip Tracy
- Zoom isn't actually end-to-end encrypted The Verge · Monica Chin
- Zoom vulnerability can leak your Windows login name and password Windows Central · Sean Endicott
- Unpatched Zoom App Bug Lets Hackers Steal Your Windows Password The Hacker News · Wang Wei
- A new Zoom vulnerability is leaking private data to strangers MSPoweruser · Anmol
- Zoom's Video Calls Aren't End-to-End Encrypted Despite Giving The Impression They Are Redmond Pie · Oliver Haslam
- Windows 10 alert: Zoom client can leak your network login credentials ZDNet · Liam Tung
- Zoom Accused of Misleading Users With ‘End-to-End Encryption’ Claims Amid Other Security Issues [Updated] MacRumors · Tim Hardwick
- Zoom Accused of Misleading Users by Claiming Meetings are End-to-End Encrypted iPhone in Canada Blog · Steve Vegvari
- Zoom claims to offer end-to-end encryption — even though that's not strictly true BetaNews · Mark Wyciślik-Wilson
- Don't believe Zoom: Its video calls are not encrypted end-to-end The Next Web · Ivan Mehta
- Zoom security bug lets attackers steal Windows passwords Mashable · Stan Schroeder
- Zoom admits meetings don't use end-to-end encryption cloudpro.co.uk · Bobby Hellard
- Zoom Falsely Claims Its Group Video Can Be End-to-End Encrypted Daring Fireball · John Gruber
- What does a pandemic say about the tech we've built? TechCrunch · Natasha Lomas
- Zoom hit with class-action lawsuit for sharing user data with Facebook CyberScoop · Sean Lyngaas
- Zoom's misleading encryption claims are just the latest problem for the popular service Six Colors · Dan Moren
- Ex-NSA hacker drops new zero-day doom for Zoom TechCrunch · Zack Whittaker
- Zoom faces a privacy and security backlash as it surges in popularity The Verge · Tom Warren
- The ‘S’ in Zoom, Stands for Security Objective-See's Blog · Patrick Wardle
- Zoom's now in the spotlight for all the wrong reasons, and more Android Authority · Tristan Rayner
- Cybersecurity experts say there should be ‘less hysteria’ about Zoom after multiple privacy and security concerns Business Insider · Martin Coulter
- Forget Zoom: Use these private video-chatting tools, instead Mashable · Jack Morse
- How to delete Zoom — Here's how to delete zoom and your zoom account … Tom's Guide · Kate Kozuch
- Zoom is Leaking Peoples' Email Addresses and Photos to Strangers VICE · Joseph Cox
- Zoom vulnerabilities could give attackers webcam, microphone access CyberScoop · Shannon Vavra
- FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic FBI.gov · Kristen Setera
- FBI warns Zoom, teleconference meetings vulnerable to hijacking CyberScoop · Shannon Vavra
- Zoom is facing questions about how private or secure it really is Associated Press · Charlotte Jee
- Zoom's privacy problems are growing as platform explodes in popularity Ars Technica · Kate Cox
- The Zoom Privacy Backlash Is Only Getting Started Wired · Lily Hay Newman
- Video Conferencing Surge Leads to Zoom-Bombing, FBI Warning and Attorney General Probe The Daily Hodl
- Zoom (ZM) Stock Price Falls 5.88%, Company Is Sued for Alleged Data Sales to Facebook coinspeaker.com · Christopher Hamman
- The Best Zoom Alternatives for Your Business TechnologyAdvice · Tamara Scott
- FBI warns about Zoom bombing as hijackers take over school and business video conferences TechRepublic · Esther Shein
- How using a VPN with Zoom can keep you and your data more secure TechRadar.com · Adam Marshall
- Zoom Tightens Privacy Policy, Says No User Videos Are Analyzed for Ads Consumer Reports · Allen St. John
- Zoom security vulnerability can be used to steal Windows login credentials BetaNews · Mark Wyciślik-Wilson
- Zoom: Room for Improvements and Hardly a Joke Beyond Search · Stephen E. Arnold
- Do you know how Zoom is using your data? Here's why you should The Guardian · Arwa Mahdawi
- N.Y. Attorney General raises concerns about Zoom's handling of sensitive data OnMSFT.com · Kareem Anderson
- Zoom's big privacy reckoning Protocol · David Pierce
- Zoom vulnerability released which allows anyone you chat with to steal your Windows Login credentials MSPoweruser · Surur
- FBI Issues Warning, NY Attorney General Makes Inquiry After Wave of Zoom Hijackings Gizmodo · Tom McKay
- Zoom facing lawsuit over sharing of data with Facebook Silicon Republic · Colm Gorey
- Zoom accused in lawsuit of improperly sharing user data with Facebook The Hill · Justin Wise
- Pandemics, Liberty and Digital Transformation The Future is Digital · Matthew Cowen
- Maybe we shouldn't use Zoom after all TechCrunch · Zack Whittaker
- How to Secure Your Zoom Meetings from Zoom-Bombing Attacks BleepingComputer · Lawrence Abrams
- ‘Zoom-bombing’: FBI warns some teleconferences, online classrooms vulnerable to hackers Fox News · Bradford Betz
- FBI warns on Zoom conference security Federal Computer Week · Mark Rockwell
- Privacy concerns are swarming around Zoom just as it's becoming everyone's new favorite videoconferencing app Business Insider · Lisa Eadicicco
- Zoom Scrutinized As Security Woes Mount Threatpost · Lindsey O'Donnell
- Zoom meetings are not as private as advertised: What you should do LaptopMag · Sean Riley
Discussion
-
@hackerfantastic
Hacker Fantastic
on x
Hi @zoom_us & @NCSC - here is an example of exploiting the Zoom Windows client using UNC path injection to expose credentials for use in SMBRelay attacks. The screen shot below shows an example UNC path link and the credentials being exposed (redacted). https://twitter.com/...
-
@_g0dmode
Mitch
on x
#Zoom chat allows you to post links such as \\x.x.x.x\xyz to attempt to capture Net-NTLM hashes if clicked by other users.
-
@0xamit
Amit Serper
on x
1. Link has to be clicked 2. Meeting has to be public for someone malicious to even join and post the link (which should probably be your in threat model anyhow) 3. This is how windows explorer works, it's vulnerable as well Conclusion: Stop using windows. #IHaveOpinions https://…
-
@bleepincomputer
@bleepincomputer
on x
Security researchers @_g0dmode and @hackerfantastic revealed tonight that the Zoom client is vulnerable to UNC injection that can be used to steal Windows login credentials or attempt to launch a program.
-
@reckless
Nilay Patel
on x
The biggest question facing Zoom is whether these gaffes are move-fast-break-things mistakes, or reflective of a deeper culture of disrespect for user privacy. Or... both. https://www.theverge.com/...
-
@reckless
Nilay Patel
on x
Also: you sort of expect these issues as consumer products go to the enterprise. But Zoom is an enterprise product, and it appears that none of its enterprise customers did any sort of worthwhile vendor security review.
-
@danamodio
Dan Amodio
on x
Worth noting that zoomAutenticationTool is a signed bin.. and you can use it as an auth trampoline for whatever script you want... https://twitter.com/... https://twitter.com/...
-
@random_walker
Arvind Narayanan
on x
Let's make this simple: Zoom is malware. https://twitter.com/...
-
@random_walker
Arvind Narayanan
on x
Every day there's a fresh Zoom privacy/security horror story. Why now, all at once? It's simple: the problems aren't new but suddenly everyone is forced to use Zoom. That means more people discovering problems and also more frustration because opting out isn't an option. https://…
-
@slightlylate
Alex Russell
on x
Move everything you possibly can to the web and don't look back. https://twitter.com/...
-
@ehn
Andreas Ehn
on x
As anyone who has built desktop software at scale can attest to, in the typical user's home/office environment, “just works” is indistinguishable from malware. This unfortunate situation is a byproduct of the cat-and-mouse game between actual attackers and system engineers. 🤷♂️ …
-
@alexstamos
Alex Stamos
on x
This week is going to be a critical one for Zoom and $ZM shareholders. This is going to get worse, as the entire infosec world descends on a spectacularly complicated product with lots of attack surface and some sketchy design trade-offs. An opportunity for a trust turn-around. h…
-
@dhh
@dhh
on x
Here's how they're abusing the OSX installer to avoid need you to authorize the installation (a good malware trick). https://twitter.com/... https://twitter.com/...
-
@profcarroll
@profcarroll
on x
Folks love Zoom because it just ‘works’ but one of the ways it seems so effortless is how they bypass security established to prevent malware. https://twitter.com/...
-
@stshank
Stephen Shankland
on x
End to middle ≠ end to end. By Zoom's definition, Gmail could be E2E encrypted even though it's sitting on a Google server. That lets Google do useful things (search, spam filtering), but it means Google doesn't get to brag email is E2E encrypted. https://twitter.com/...
-
@trevortimm
Trevor Timm
on x
Zoom says all over the place—on its app, website, security white paper—that its video calls are “end-to-end encrypted,” but when @theintercept asked them about it they said: “Currently, it is not possible to enable E2E encryption for Zoom video meetings.” https://theintercept.com…
-
@shanvav
Shannon Vavra
on x
The FBI issued a warning today that Zoom and other teleconferencing may not be as private/secure as advertised. As remote work/classes surge w/ coronavirus, this raises privacy, security, & possibly national security issues, as world leaders use Zoom too. https://www.cyberscoop.c…
-
@mgsiegler
M.G. Siegler
on x
Unclear if the Zoomlash is going to last two weeks, two days, or two minutes in our current distorted temporal state of reality. https://twitter.com/...
-
@cradvocacy
@cradvocacy
on x
“Zoom should update their terms to ensure that data collected during meetings from any participant or host is explicitly excluded from any advertising or marketing use...” says CR's @JustinBrookman. See our tips for enhancing your privacy on Zoom: https://www.consumerreports.org/…
-
@jason_koebler
Jason Koebler
on x
Design flaw in Zoom lets random strangers video call people and also leaks photos and email addresses of anyone using nonstandard email addresses: https://www.vice.com/...
-
@vice
@vice
on x
A Zoom user filed a class action lawsuit against the company for sending data to Facebook, arguing that Zoom violated California's new data protection law. https://www.vice.com/...
-
@random_walker
Arvind Narayanan
on x
Zoom is also a privacy disaster https://blogs.harvard.edu/... The creepiest feature is attention tracking. If it's on, it reports to the host if a user clicks away from the Zoom window for 30 seconds. As we all know, your boss constantly watching your screen is a great way to wor…
-
@yuanfenyang
Yuan Yang
on x
The UK: We really shouldn't give our sensitive data to Huawei if we can't guarantee the integrity of its security Also the UK: We should give it all to Zoom instead Also see: https://theintercept.com/... https://twitter.com/...
-
@ow
@ow
on x
Zoom is such a dodgy/misleading company across the board and using it should be reconsidered 🙅♀️ https://theintercept.com/...
-
@jilliancyork
@jilliancyork
on x
I was willing to write off the other stuff about Zoom, but not this. I'll be looking for a better solution for anything personal. https://theintercept.com/...
-
@profcarroll
@profcarroll
on x
Zoom: “We take privacy seriously.” NY AG: “We too take privacy seriously.” https://www.nytimes.com/...
-
@fbiboston
FBI Boston
on x
FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic: As large numbers of people turn to video-teleconferencing (VTC) platforms to stay connected in the wake of the COVID-19 crisis, reports of VTC hijacking are emerging ... https://www.fbi.gov/...
-
@joshgerstein
Josh Gerstein
on x
‘Without end-to-end encryption, Zoom has the technical ability to spy on private video meetings and could be compelled to hand over recordings of meetings to governments or law enforcement in response to legal requests.’ https://twitter.com/...
-
@mltellado
Marta L. Tellado
on x
Great reporting by @allenstjohn who wrote about the privacy concerns of using Zoom. Thanks, Doc Searls @dsearls for elevating this issue & calling @consumerreports “the greatest moral conscience in the history of business” https://www.consumerreports.org/ ...