Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Zoom is leaking your sensitive data to strangers, allowing hackers access to Windows password: Report
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Zoom is leaking your sensitive data to strangers, allowing hackers access to Windows password: Report

Zoom is leaking your sensitive data to strangers, allowing hackers access to Windows password: Report

tech2 News Staff • April 2, 2020, 15:59:52 IST
Whatsapp Facebook Twitter

After the iOS vulnerability found last week, security researchers claim to have found a bunch of new vulnerabilities in the app.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Zoom is leaking your sensitive data to strangers, allowing hackers access to Windows password: Report

With lockdowns around the world forcing people to stay in, video conferencing app Zoom’s popularity has exploded like never before. This week,  **Zoom** **became the top free app** on the App Store and Google Play Store. Although, while on one hand, Zoom was becoming a popular choice for people trying to connect with friends and office colleagues, on the other hand, the app was found to be sending iOS users’ data to Facebook without their knowledge. Zoom, however, patched the issue soon after the discovery and refused any such activity. Now, just a week after that, a few security researchers claim to have found a bunch of other vulnerabilities in the app. [caption id=“attachment_8197001” align=“alignnone” width=“1024”] ![Zoom video conferencing app](https://images.firstpost.com/wp-content/uploads/2020/03/zoom-1024.jpg) Zoom video conferencing app[/caption] The first flaw was discovered by a security researcher who goes by the handle @g0dmode on Twitter, and it’s about UNC paths. Per the researchers, the Zoom on Windows is converting networking UNC paths into a clickable link in the chat message. Essentially, this means, that the Windows version of the app is allowing hackers to capture Windows passwords.

#Zoom chat allows you to post links such as \\x.x.x.x\xyz to attempt to capture Net-NTLM hashes if clicked by other users.

— Mitch (@_g0dmode) March 23, 2020

Turns out that @zoom_us UNC path rendering bug is even worse than initially observed, you can hide the UNC magic and completely disable the prompting for running code... (this will affect other applications in a similar way using RichText edit boxes etc., for all ye naysayers...) https://t.co/YqnjNy5RyO

— hackerfantastic.x (@hackerfantastic) April 2, 2020
More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

Besides that, Zoom app on Mac, there are two distinct loopholes, which can allow an attacker to can gain access to the computer once exploited and install malware or spyware, without letting users know about the backdoor entry. Apparently, this loophole comes via the installer for the app, which can easily be injected with malicious codes. This flaw was spotted by researcher Patrick Wardle and was first reported by  TechCrunch.

TechCrunch/@zackwhittaker: "🍎 has pushed a silent update to all Macs removing a ...web server installed by Zoom"

How? MRTConfigData_10_14-1.45 (MRT is 🍎's built-in "Malware Removal Tool") added "MACOS.354c063", a new encoded signature & removal routine 😯😅

H/T @howardnoakley pic.twitter.com/RUCSDmR2sU

— Patrick Wardle (@patrickwardle) July 11, 2019

Another security researcher re-iterated the same issue.

Ever wondered how the @zoom_us macOS installer does it’s job without you ever clicking install? Turns out they (ab)use preinstallation scripts, manually unpack the app using a bundled 7zip and install it to /Applications if the current user is in the admin group (no root needed). pic.twitter.com/qgQ1XdU11M

— Felix (@c1truz_) March 30, 2020

Wardle found another bug in the Mac client, that could allow an attacker to inject malicious code to access the webcam and microphone of the system. Take a deep breath, because that’s not all! Another report by Vice claims that Zoom has an issue that is grouping individuals to a particular ‘Company Directory’, which is otherwise meant for users within the same company with similar email domain. Due to the issue, reportedly, personal information of users, such as email address and photo, is available to unknown users in an unsolicited manner.

STORY CONTINUES BELOW THIS AD

Zoom responded to the report with a response saying that they had blacklisted the domain that were spamming users:

Zoom maintains a blacklist of domains and regularly proactively identifies domains to be added. With regards to the specific domains that you highlighted in your note, those are now blacklisted.

Zoom also says that it allows users to request other domains to be removed from the Company Directory feature.

Tags
Zoom Zoom app Zoom iOS Zoom vulnerability Zoom Mac app Zoom Windows client Zoom video conferencing
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV