【1982 Archives】
Zoom982 Archives the videoconferencing software that's skyrocketed in popularity as much of the globe sits at home due to the coronavirus outbreak, is quickly turning into a privacy and security nightmare.
BleepingComputer reports about a newly found vulnerability in Zoom that allows an attacker to steal Windows login credentials from other users. The problem lies with the way Zoom's chat handles links, as it converts Windows networking UNC (Universal Naming Convention) paths into clickable links. If a user clicks on such a link, Windows will leak the user's Windows login name and password.
The good thing is that the password is hashed; but the bad thing is that it is in many cases simple to reveal it using password recovery tools such as Hashcat.
The vulnerability was first found by security researcher @_g0dmode and verified by security researcher Matthew Hickey. Additionally, Hickey told the news outlet that this vulnerability can be used to launch programs on a victim's computer when they click on a link, though Windows will (by default) at least give a security warning before launching the program.
As far as security vulnerabilities go, this one is pretty bad, as it doesn't require a lot of knowledge to exploit. It does require the victim to actually click on a link, and it can be mitigated by tinkering with Windows' security settings, but it's definitely something Zoom should fix by changing the way the platform's chat handles UNC links.
In the meantime, for a quick fix, go to Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers and set to "Deny all".
Mashable has contacted Zoom for comment on this story, and we'll update it when we hear back.
SEE ALSO: Zoom's iOS app no longer sends data to FacebookThis is not the only privacy/security-related issue that has been unearthed at Zoom in the past couple of weeks. Just yesterday, The Intercept reported that Zoom doesn't actually use an end-to-end encrypted connection for its calls, despite claiming to do so. There's also the issue of leaking users' emails and photos to unrelated parties, and the fact that the company's iOS app, until recently, sent data to Facebook for no good reason.
Zoom software also has a couple of worrying privacy features, and although this isn't Zoom's fault, it's worth noting that hackers are using the app's newfound popularity to trick users into downloading malware.
Topics Cybersecurity
Search
Categories
Latest Posts
Best Max streaming deal: Save 20% on annual subscriptions
2025-06-26 10:55Facebook's Oculus is testing in
2025-06-26 09:12Popular Posts
NYT Strands hints, answers for April 26
2025-06-26 10:17What to expect from Mobile World Congress: Samsung, Huawei, and more
2025-06-26 09:55Pixar's 'Luca' is the ultimate summer vacation fantasy: Movie review
2025-06-26 09:34Dustin Hoffman accused of groping co
2025-06-26 09:035 Ways to Access a Locked Windows Account
2025-06-26 08:44Featured Posts
Best iPad deal: Save $132 on Apple iPad (10th Gen)
2025-06-26 11:12Why passengers might actually feel safe in Zoox self
2025-06-26 11:05Pixar's 'Luca' is the ultimate summer vacation fantasy: Movie review
2025-06-26 09:45Softbank's new Leica
2025-06-26 09:15Put Me In, Coach!
2025-06-26 08:34Popular Articles
How to change the time on your Fitbit
2025-06-26 10:02OnePlus to become a sub
2025-06-26 09:18Keeping Hope Alive
2025-06-26 08:43Newsletter
Subscribe to our newsletter for the latest updates.
Comments (4275)
Style Information Network
Asus VivoWatch 6 AERO measures blood pressure and ECG
2025-06-26 10:40Habit Information Network
Tamagotchi is back, and this time it's literally clinging to your arm
2025-06-26 10:16Fresh Information Network
How to change your Netflix password
2025-06-26 10:11Evergreen Information Network
Sexual abuse in the music industry gets spotlight with #MeNoMore
2025-06-26 09:17Wisdom Convergence Information Network
Best headphones deal: Save up to 51% on Beats at Amazon
2025-06-26 08:33