ASA-2019-00410 – Zoom: Information Disclosure by forcing users to join a video call with the video camera active


Allele Security Alert

ASA-2019-00410

Identifier(s)

ASA-2019-00410, CVE-2019-13450

Title

Information Disclosure by forcing users to join a video call with the video camera active

Vendor(s)

Zoom Video Communications, Inc

Product(s)

Zoom Client

Affected version(s)

Zoom Client versions 4.4.4 and earlier

Fixed version(s)

Unknown

Proof of concept

Yes

Description

Remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424.

Technical details

Unknown

Credits

Jonathan Leitschuh

Reference(s)

Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!
https://medium.com/@jonathan.leitschuh/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5

Zoom Vulnerability POC
https://github.com/JLLeitschuh/zoom_vulnerability_poc

Zoom Response Video-On Vulnerability
https://assets.zoom.us/docs/pdf/Zoom+Response+Video-On+Vulnerability.pdf

Response to Video-On Concern
https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/

Twitter
https://twitter.com/jlleitschuh/status/1148632996330844160?s=12

CVE-2019–13449
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019–13449

CVE-2019–13449
https://nvd.nist.gov/vuln/detail/CVE-2019–13449

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 9, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.