Zoom Zero Day: 4+ Million Webcams...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

## CVE-Numbers DOS Vulnerability — Fixed in Client version 4.4.2 — CVE-2019–13449 Information Disclosure (Webcam) — Unpatched —CVE-2019–13450 ## UPDATE — July 9th (am) As far as I can tell this vulnerability also impacts Ringcentral. Ringcentral for their web conference system is a white labeled Zoom system. ## UPDATE — July 9th (pm) According to Zoom, they will have a fix shipped by midnight tonight pacific time removing the hidden web server; hopefully this patches the most glaring parts of this vulnerability. The Zoom CEO has also assured us that they will be updating their application to further protect users privacy. ## Foreword This vulnerability allows any website to forcibly join a user to a Zoom call, with their video camera activated, without the user's permission. On top of this, this vulnerability would have allowed any webpage to DOS (Denial of Service) a Mac by repeatedly joining a user to an invalid call. Additionally, if you’ve ever installed the Zoom client and...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息