ASA-2019-00409 – Zoom: Denial of Service by repeatedly joining a user to an invalid call


Allele Security Alert

ASA-2019-00409

Identifier(s)

ASA-2019-00409, CVE-2019-13449

Title

Denial of Service by repeatedly joining a user to an invalid call

Vendor(s)

Zoom Video Communications, Inc

Product(s)

Zoom Client

Affected version(s)

Zoom Client versions before 4.4.2

Fixed version(s)

Zoom Client version 4.4.2

Proof of concept

Yes

Description

Remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost web server on port 19421.

Technical details

Unknown

Credits

Jonathan Leitschuh

Reference(s)

Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!
https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5

Twitter
https://twitter.com/jlleitschuh/status/1148632996330844160?s=12 

CVE-2019–13449
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019–13449

CVE-2019–13449
https://nvd.nist.gov/vuln/detail/CVE-2019–13449

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 10, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.