Information Disclosure Vulnerability in Zoom
Overview
A vulnerability has been reported in Zoom which could be exploited by a remote attacker to join meetings that are currently active leading to sensitive information disclosure.
Description
This vulnerability exists in Zoom due to weak authentication methods used by Zoom during video conferencing. The video
conference does not require a conference password, but only requires a meeting ID password of 9, 10 or 11 digits. A remote attacker could exploit this vulnerability by pre -generating a list of potential meeting IDs and prepare a URI_ string for joining a meeting which returned a response indicating "Valid Meeting ID found" if the ID was linked to an active conference or an "Invalid Meeting ID" for any inactivity.
Successful exploitation of this vulnerability could allow a remote attacker to join an active video conference and obtain access to sensitive information such as documents, presentations, etc.
A vulnerability has been reported in Zoom which could be exploited by a remote attacker to join meetings that are currently active leading to sensitive information disclosure.
Description
This vulnerability exists in Zoom due to weak authentication methods used by Zoom during video conferencing. The video
conference does not require a conference password, but only requires a meeting ID password of 9, 10 or 11 digits. A remote attacker could exploit this vulnerability by pre -generating a list of potential meeting IDs and prepare a URI_ string for joining a meeting which returned a response indicating "Valid Meeting ID found" if the ID was linked to an active conference or an "Invalid Meeting ID" for any inactivity.
Successful exploitation of this vulnerability could allow a remote attacker to join an active video conference and obtain access to sensitive information such as documents, presentations, etc.
Comments
Post a Comment