ZoomÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-13450£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


MacµÄZoom app 4.4.4°æ±¾


Îó²î¸ÅÊö


ZoomÊÇÆóÒµÊÓÆµÍ¨Ñ¶ÁìÓòµÄÏòµ¼Õߣ¬ £¬£¬£¬£¬ÊÇÊÓÆµºÍÒôƵ¾Û»á£¬ £¬£¬£¬£¬Ì¸ÌìºÍÍøÂç×êÑлá×îÊܽӴýºÍ×î¿É¿¿µÄÔÆÆ½Ì¨Ö®Ò»¡£¡£¡£¡£¡£¡£¡£


Çå¾²Ñо¿Ô±¹ûÕæÅû¶ÁËÔÚMacµçÄÔÉÏZoomÊÓÆµ¾Û»áÓ¦ÓÃÖзºÆðµÄÒ»¸öÎó²î¡£¡£¡£¡£¡£¡£¡£´ËÎó²îÔÊÐíÈκÎÍøÕ¾ÔÚδ¾­Óû§ÔÊÐíµÄÇéÐÎÏÂÇ¿Ðн«Óû§ÅþÁ¬µ½Zoomºô½Ð£¬ £¬£¬£¬£¬²¢¼¤»îÆäÉãÏñ»ú¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬ £¬£¬£¬£¬´ËÎó²îͨ¹ýÖØ¸´½«Óû§¼ÓÈëÎÞЧºô½Ð£¬ £¬£¬£¬£¬ÔÊÐíÈκÎÍøÒ³½øÈëDOS£¨¾Ü¾øÐ§ÀÍ£©Mac¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬ÈôÊÇÄúÒ»¾­×°ÖùýZoom¿Í»§¶ËÈ»ºó½«ÆäÐ¶ÔØ£¬ £¬£¬£¬£¬ÄÇôÄúµÄÅÌËã»úÉÏÈÔÈ»ÓÐÒ»¸ölocalhost WebЧÀÍÆ÷¿ÉÒÔΪÄúÖØÐÂ×°ÖÃZoom¿Í»§¶Ë£¬ £¬£¬£¬£¬³ýÁË»á¼ûÍøÒ³Ö®Í⣬ £¬£¬£¬£¬ÄúÎÞÐè´ú±íÄú¾ÙÐÐÈκÎÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£


¸ÃÎó²îʹÓÃZoomÈí¼þµÄµã»÷¼ÓÈ빦Ч£¬ £¬£¬£¬£¬ÔÊÐí×Ô¶¯¼¤»îϵͳÉÏ×°ÖõÄÓ¦ÓóÌÐò£¬ £¬£¬£¬£¬Í¨¹ýWebä¯ÀÀÆ÷¼ÓÈëÊÓÆµ¾Û»á£¬ £¬£¬£¬£¬Ö»Ðèµã»÷Ô¼ÇëÁ´½Ó£¬ £¬£¬£¬£¬Ô¼ÇëÁ´½ÓµÄʾÀýÊÇ£ºhttps://zoom.us/j/492468757£¬ £¬£¬£¬£¬´Ë¹¦Ð§µÄʵÏÖʹÓÃÕìÌý¶Ë¿Ú19421µÄÍâµØWebЧÀÍÆ÷£¬ £¬£¬£¬£¬¸ÃЧÀÍÆ÷¿ÉÒÔͨ¹ýHTTPS GET²ÎÊýÔÚûÓÐÐëÒªÊÚȨÏÂÁîµÄÇéÐÎÏÂÎüÊÕ¡£¡£¡£¡£¡£¡£¡£Ëü»¹ÔÊÐíÔÚÓû§µÄWebä¯ÀÀÆ÷Öз­¿ªµÄÈκÎÍøÕ¾ÓëÆä¾ÙÐн»»¥¡£¡£¡£¡£¡£¡£¡£ÔÚMacÉÏ£¬ £¬£¬£¬£¬ÈôÊÇÄãÒ»¾­×°ÖÃÁËZoom£¬ £¬£¬£¬£¬ÄãµÄÍâµØ»úеÉÏÓÐһ̨ÔËÐÐÔÚ¶Ë¿Ú19421ÉϵÄWebЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Äã¿ÉÒÔͨ¹ýÔÚÖÕ¶ËÖÐÔËÐÐlsof -i£º19421À´È·ÈϸÃЧÀÍÆ÷±£´æ¡£¡£¡£¡£¡£¡£¡£


¸ÃÎó²î¿ÉÄÜ»áʹȫÇò¶à´ï750,000¼ÒʹÓÃZoom¾ÙÐÐÒ»Ñùƽ³£ÓªÒµµÄ¹«Ë¾ÆØ¹â¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://github.com/JLLeitschuh/zoom_vulnerability_poc¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ZoomÐÞ²¹ÁËÎó²î¡£¡£¡£¡£¡£¡£¡£


»º½â²½·¥£ºÈ·±£×Ô¼ºµÄMacÓ¦ÓÃÊÇ×îеIJ¢½ûÓÃÔÊÐíZoom·­¿ªÆäÏà»ú¼ÓÈë¾Û»áµÄÉèÖ㬠£¬£¬£¬£¬¼ûÏÂͼ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


²Î¿¼Á´½Ó


https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5