Allele Security Alert
ASA-2019-00410
Identifier(s)
ASA-2019-00410, CVE-2019-13450
Title
Information Disclosure by forcing users to join a video call with the video camera active
Vendor(s)
Zoom Video Communications, Inc
Product(s)
Zoom Client
Affected version(s)
Zoom Client versions 4.4.4 and earlier
Fixed version(s)
Unknown
Proof of concept
Yes
Description
Remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424.
Technical details
Unknown
Credits
Jonathan Leitschuh
Reference(s)
Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!
https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5
Zoom Vulnerability POC
https://github.com/JLLeitschuh/zoom_vulnerability_poc
Zoom Response Video-On Vulnerability
https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf
Response to Video-On Concern
https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/
Twitter
https://twitter.com/jlleitschuh/status/1148632996330844160?s=12
CVE-2019–13449
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019–13449
CVE-2019–13449
https://nvd.nist.gov/vuln/detail/CVE-2019–13449
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: July 9, 2019