Zoom Ô¶³Ì´úÂëÖ´ÐÐ0 day©¶´

Ðû²¼Ê±¼ä 2021-04-12

0x00 ©¶´¸ÅÊö

CVE  ID


ʱ     ¼ä

2021-04-12

Àà   ÐÍ

RCE

µÈ     ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


PoC/EXP


ÔÚÒ°ÀûÓÃ


 

0x01 ©¶´ÏêÇé

image.png

 

Zoom ÊÇÒ»¸ö¼òµ¥Ò×ÓõÄÔÚÏßÊÓÆµ»áÒéÈí¼þ,ËüÌṩÁËÊÓÆµÍ¨ÐÅ¡¢ÒôƵͨÐÅ¡¢ÆÁÄ»¹²ÏíÌåÑéÒÔ¼°ÔÚÏßȺ×éÁÄÌ칦Ч ¡£

Pwn2Own¾ºÈüÊÇÓɰ×Ã±ÍøÂçÄþ¾²×¨ÒµÈËÔ±ºÍÍŶӼÓÈ룬ÒÔ¾ºÕù·¢ÏÖÁ÷ÐÐÈí¼þºÍ·þÎñÖеĴíÎóµÄ¾ºÈü ¡£

2021Äê04ÔÂ07ÈÕ£¬Á½ÃûºÉÀ¼°×ñÄþ¾²×¨¼ÒÔÚ¼ÓÈëÄê¶È¼ÆËã»úºÚ¿Í´óÈüPwn2OwnʱÔÚZoomÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Â©¶´£¬´Ë©¶´½áºÏÁËÈý¸ö©¶´¹¥»÷Á´À´¿ØÖÆÔ¶³Ìϵͳ£¬ÀÖ³ÉÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»ÔÚLAN¡¢WAN»òInternetÉϵÄÔ¶³Ì¼ÆËã»úÉÏÖ´ÐдúÂë ¡£´ËÍ⣬¸Ã©¶´µÄÀûÓÃÖ»ÐèÓû§½øÐÐÒ»´ÎZoomͨ»°£¬¶øÎÞÐèÓû§½»»¥ ¡£

Pwn2Own×éÖ¯ÒѾ­ÔÚtwitterÉÏÐû²¼Á˸é¶´µÄgifÓ¦ÓÃÑÝʾ£¬Í¨¹ýÔÚÔËÐÐZoomµÄϵͳÉÏ´ò¿ª¼ÆËãÆ÷Calc.exe ¡£

image.png

 

Ó°Ï췶Χ

Windows°æZoom

Mac°æZoom

£¨iOS¼°AndroidĿǰÉÐδ²âÊÔ£¬ä¯ÀÀÆ÷°æ²»ÊÜÓ°Ïì ¡££©

 

 

0x02 ´¦Öý¨Òé

ÓÉÓÚZoom»¹Ã»ÓÐʱ¼äÐÞ¸´´Ë©¶´£¬Òò´Ë¸Ã©¶´µÄ¾ßÌå¼¼Êõϸ½ÚÈÔÔÚ±£ÃÜÖÐ ¡£Ä¿Ç°£¬Ö»ÓÐÁ½ÃûÄþ¾²×¨¼ÒºÍZoomÖªµÀ¸Ã©¶´µÄÊÂÇéÔ­Àí£¬½¨Ò鹨עZoom¹Ù·½Ðû²¼µÄÄþ¾²¸üР¡£

ÏÂÔØÁ´½Ó£º

https://www.zoom.us/download

 

0x03 ²Î¿¼Á´½Ó

https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/

https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/#ftag=RSSbaffb68

https://twitter.com/i/status/1379855435730149378

 

 

0x04 ʱ¼äÏß

2021-04-07  KeuperºÍAlkemade·¢ÏÖ©¶´

2021-04-12  VSRCÐû²¼Äþ¾²Í¨¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png