Zoom bug can let hackers steal your Windows password

| | San Francisco
1 2 3 4 5
  • 0

Zoom bug can let hackers steal your Windows password

Thursday, 02 April 2020 | IANS | San Francisco

Zoom bug can let hackers steal your Windows password

Slammed for the lack of users privacy and security by the US Federal Bureau of Investigation (FBI) and cybersecurity experts, video meeting app Zoom is also prone to hacking, a new report has claimed, saying an unpatched bug can let hackers steal users Windows password.

The �Zoom client for Windows' is vulnerable to the 'UNC path injection' vulnerability that could let remote attackers steal login credentials for victims' Windows systems, reports TheHacckeNews.

The latest finding by cybersecurity expert @_g0dmode, has also been "confirmed by researcher Matthew Hickey and Mohamed A. Baset,' the report said late Wednesday.

The attack involves the "SMBRelay technique" wherein Windows automatically exposes a user's login username and NTLM password hashes to a remote server, when attempting to connect and download a file hosted on it.

"The attack is possible only because Zoom for Windows supports remote UNC paths, which converts such potentially insecure URLs into hyperlinks for recipients in a personal or group chat," the report claimed.

Besides Windows credentials, the vulnerability can also be exploited to launch any programme present on a targeted computer.

Zoom has been notified of this bug but the flaw is yet to be fixed.

"Users are advised to either use an alternative video conferencing software or Zoom in your web browser instead of the dedicated client app," said the report.

Another media report claimed that Zoom doesn't use end-to-end encryption to protect calling data of its users.

As businesses, schools and colleges and millions of SMBs use video conferencing tool Zoom during the work-from-home scenario, the US Federal Bureau of Investigation (FBI) has warned people about porn material being popped up during the video meetings.

The Boston branch of the law enforcement agency said it has received multiple reports of Zoom conferences being disrupted by pornographic and/or hate images and threatening language.

The video conferencing app late last month updated its iOS app to remove the software development kit (SDK) that was providing users' data to Facebook through the Login with Facebook feature.
 

Trending News

more

State Editions

Sports and players at the core of development roadmap: CM

09 March 2025 | Staff Reporter | Bhopal

BHEL celebrates Women’s Day

09 March 2025 | Staff Reporter | Bhopal

150 female cops, their families benefited with free health camp

09 March 2025 | Staff Reporter | Bhopal

Bhopal-Bilaspur Exp operated by all women staff

09 March 2025 | Staff Reporter | Bhopal

Indian Railways equips female RPF cops with pepper sprays

09 March 2025 | Staff Reporter | Bhopal

Gaur inaugurates Refrigerated Centrifuge Machine at BMHRC

09 March 2025 | Staff Reporter | Bhopal

Sports and players at the core of development roadmap: CM

09 March 2025 | Staff Reporter | Bhopal

BHEL celebrates Women’s Day

09 March 2025 | Staff Reporter | Bhopal

Sunday Edition

The timeless charm of vintage cars

02 March 2025 | Gyaneshwar Dayal | Agenda

Waah Womaniya

09 March 2025 | Abhi Singhal | Agenda

The Power of HER Plates

09 March 2025 | Team Agenda | Agenda

EMBRACING THE SPIRIT OF HOLI SWEETNESS

09 March 2025 | Team Agenda | Agenda

Dipped in Holi

09 March 2025 | SAKSHI PRIYA | Agenda

The timeless charm of vintage cars

02 March 2025 | Gyaneshwar Dayal | Agenda

Waah Womaniya

09 March 2025 | Abhi Singhal | Agenda