Information Disclosure Vulnerability in Zoom

Overview

A  vulnerability has been reported in Zoom which could be exploited by a remote attacker to join meetings that are currently active leading to sensitive information disclosure.

Description

This vulnerability exists in  Zoom due to weak authentication methods used by Zoom during video conferencing.  The video
conference does not require a  conference password,  but only requires a  meeting  ID  password of  9, 10  or  11  digits.  A  remote attacker could exploit this vulnerability by pre  -generating a list of potential meeting  IDs and prepare a URI_  string for joining a meeting which returned a response indicating "Valid  Meeting  ID found"  if the ID was linked to an active conference or an  "Invalid Meeting  ID" for any inactivity.
Successful exploitation of this vulnerability could allow a  remote attacker to join an active video conference and obtain access to sensitive information such as documents, presentations,  etc.

Comments

Popular posts from this blog

Some Dark web Links

How to join Cyber Cell or Cyber Crime Department in India || Exam or Direct or Skills???

ATM HACKING TOOL TRENDING ON DARK WEB