Information Disclosure Vulnerability in Zoom

Overview

A  vulnerability has been reported in Zoom which could be exploited by a remote attacker to join meetings that are currently active leading to sensitive information disclosure.

Description

This vulnerability exists in  Zoom due to weak authentication methods used by Zoom during video conferencing.  The video
conference does not require a  conference password,  but only requires a  meeting  ID  password of  9, 10  or  11  digits.  A  remote attacker could exploit this vulnerability by pre  -generating a list of potential meeting  IDs and prepare a URI_  string for joining a meeting which returned a response indicating "Valid  Meeting  ID found"  if the ID was linked to an active conference or an  "Invalid Meeting  ID" for any inactivity.
Successful exploitation of this vulnerability could allow a  remote attacker to join an active video conference and obtain access to sensitive information such as documents, presentations,  etc.

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Some Dark web Links

Cyber Security Audits