Zoom Ô¶³Ì´úÂëÖ´ÐÐ0 dayÎó²î

Ðû²¼Ê±¼ä 2021-04-12

0x00 Îó²î¸ÅÊö

CVE  ID


ʱ     ¼ä

2021-04-12

Àà   ÐÍ

RCE

µÈ     ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP


ÔÚҰʹÓÃ


 

0x01 Îó²îÏêÇé

image.png

 

Zoom ÊÇÒ»¸ö¼òÆÓÒ×ÓõÄÔÚÏßÊÓÆµ¾Û»áÈí¼þ,ËüÌṩÁËÊÓÆµÍ¨Ñ¶¡¢ÒôƵͨѶ¡¢ÆÁÄ»¹²ÏíÌåÑéÒÔ¼°ÔÚÏßȺ×é̸Ì칦Ч¡£¡£¡£

Pwn2Own¾ºÈüÊÇÓɰ×Ã±ÍøÂçÇ徲רҵְԱºÍÍŶӼÓÈ룬 £¬£¬ÒÔ¾ºÕù·¢Ã÷Ê¢ÐÐÈí¼þºÍЧÀÍÖеĹýʧµÄ¾ºÈü¡£¡£¡£

2021Äê04ÔÂ07ÈÕ£¬ £¬£¬Á½ÃûºÉÀ¼°×ñÇ徲ר¼ÒÔÚ¼ÓÈëÄê¶ÈÅÌËã»úºÚ¿Í´óÈüPwn2OwnʱÔÚZoomÖз¢Ã÷ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬ £¬£¬´ËÎó²îÁ¬ÏµÁËÈý¸öÎó²î¹¥»÷Á´À´¿ØÖÆÔ¶³Ìϵͳ£¬ £¬£¬ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚLAN¡¢WAN»òInternetÉϵÄÔ¶³ÌÅÌËã»úÉÏÖ´ÐдúÂë¡£¡£¡£±ðµÄ£¬ £¬£¬¸ÃÎó²îµÄʹÓÃÖ»ÐèÓû§¾ÙÐÐÒ»´ÎZoomͨ»°£¬ £¬£¬¶øÎÞÐèÓû§½»»¥¡£¡£¡£

Pwn2Own×éÖ¯ÒѾ­ÔÚtwitterÉÏÐû²¼Á˸ÃÎó²îµÄgifÓ¦ÓÃÑÝʾ£¬ £¬£¬Í¨¹ýÔÚÔËÐÐZoomµÄϵͳÉÏ·­¿ªÅÌËãÆ÷Calc.exe¡£¡£¡£

image.png

 

Ó°Ïì¹æÄ£

Windows°æZoom

Mac°æZoom

£¨iOS¼°AndroidÏÖÔÚÉÐδ²âÊÔ£¬ £¬£¬ä¯ÀÀÆ÷°æ²»ÊÜÓ°Ïì¡£¡£¡££©

 

 

0x02 ´¦Öóͷ£½¨Òé

ÓÉÓÚZoom»¹Ã»ÓÐʱ¼äÐÞ¸´´ËÎó²î£¬ £¬£¬Òò´Ë¸ÃÎó²îµÄÏêϸÊÖÒÕϸ½ÚÈÔÔÚ±£ÃÜÖС£¡£¡£ÏÖÔÚ£¬ £¬£¬Ö»ÓÐÁ½ÃûÇ徲ר¼ÒºÍZoomÖªµÀ¸ÃÎó²îµÄÊÂÇéÔ­Àí£¬ £¬£¬½¨Ò鹨עZoom¹Ù·½Ðû²¼µÄÇå¾²¸üС£¡£¡£

ÏÂÔØÁ´½Ó£º

https://www.zoom.us/download

 

0x03 ²Î¿¼Á´½Ó

https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/

https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/#ftag=RSSbaffb68

https://twitter.com/i/status/1379855435730149378

 

 

0x04 ʱ¼äÏß

2021-04-07  KeuperºÍAlkemade·¢Ã÷Îó²î

2021-04-12  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png