ZoomÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13450£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


MacµÄZoom app 4.4.4°æ±¾


·ì϶¸ÅÊö


ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄ¸¨µ¼Õߣ¬ÊÇÊÓÆµºÍÒôƵ»áÒ飬̸ÌìºÍÍøÂç×êÑлá×îÊÜÓ­½ÓºÍ×î¿¿µÃסµÄÔÆÆ½Ì¨Ö®Ò»¡£


°²È«×êÑÐÔ±¹«¿ªÅû¶ÁËÔÚMacµçÄÔÉÏZoomÊÓÆµ»áÒéÀûÓÃÖгöÏÖµÄÒ»¸ö·ì϶¡£´Ë·ì϶ÔÊÐíÈκÎÍøÕ¾ÔÚδ¾­Óû§Ðí¿ÉµÄÇé¿öÏÂÇ¿Ðн«Óû§Ïνӵ½Zoomºô½Ð£¬²¢¼¤»îÆäÉãÏñ»ú¡£³ý´ËÖ®±í£¬´Ë·ì϶ͨ¹ý·´¸´½«Óû§²ÎÓëÎÞЧºô½Ð£¬ÔÊÐíÈκÎÍøÒ³½øÈëDOS£¨»Ø¾ø·þÎñ£©Mac¡£´Ë±í£¬ÈôÊÇÄúÒѾ­×°ÖùýZoom¿Í»§¶Ë¶øºó½«ÆäÐ¶ÔØ£¬ÄÇôÄúµÄÍÆËã»úÉÏÒÀÈ»ÓÐÒ»¸ölocalhost Web·þÎñÆ÷¿ÉÒÔΪÄú³ÁÐÂ×°ÖÃZoom¿Í»§¶Ë£¬³ýÁ˽ӼûÍøÒ³Ö®±í£¬ÄúÎÞÐè´ú±íÄú½øÐÐÈκÎÓû§½»»¥¡£


¸Ã·ì϶ÀûÓÃZoomÈí¼þµÄµã»÷²ÎÓëÖ°ÄÜ£¬ÔÊÐí×Ô¶¯¼¤»îϵͳÉÏ×°ÖõÄÀûÓ÷¨Ê½£¬Í¨¹ýWebä¯ÀÀÆ÷²ÎÓëÊÓÆµ»áÒ飬ֻÐèµã»÷Ô¼ÇëÁ´½Ó£¬Ô¼ÇëÁ´½ÓµÄʾÀýÊÇ£ºhttps://zoom.us/j/492468757£¬´ËÖ°ÄܵÄʵÏÖÀûÓÃÕìÌý¶Ë¿Ú19421µÄ±¾µØWeb·þÎñÆ÷£¬¸Ã·þÎñÆ÷Äܹ»Í¨¹ýHTTPS GET²ÎÊýÔÚûÓбØÒªÊÚȨºÅÁîµÄÇé¿öϽӹÜ¡£Ëü»¹ÔÊÐíÔÚÓû§µÄWebä¯ÀÀÆ÷Öдò¿ªµÄÈκÎÍøÕ¾ÓëÆä½øÐн»»¥¡£ÔÚMacÉÏ£¬ÈôÊÇÄãÒѾ­×°ÖÃÁËZoom£¬ÄãµÄ±¾µØ»úеÉÏÓÐһ̨ÔËÐÐÔÚ¶Ë¿Ú19421ÉϵÄWeb·þÎñÆ÷¡£ÄãÄܹ»Í¨¹ýÔÚÖÕ¶ËÖÐÔËÐÐlsof -i£º19421À´È·Èϸ÷þÎñÆ÷´æÔÚ¡£


¸Ã·ì϶¿ÉÄÜ»áʹȫÇò¶à´ï750,000¼ÒʹÓÃZoom½øÐÐÈÕ³£ÒµÎñµÄ¹«Ë¾ÆØ¹â¡£


·ì϶ÑéÖ¤


POC£ºhttps://github.com/JLLeitschuh/zoom_vulnerability_poc¡£


½¨¸´½¨Òé


Zoom½¨²¹ÁË·ì϶¡£


»º½â´ëÊ©£ºÈ·±£×Ô¼ºµÄMacÀûÓÃÊÇ×îеIJ¢½ûÓÃÔÊÐíZoom´ò¿ªÆäÏà»ú²ÎÓë»áÒéµÄÉèÖ㬼ûÏÂͼ£º


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²Î¿¼Á´½Ó


https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5