financetom
Technology
financetom
/
Technology
/
Zoom bug can let hackers steal your Windows password
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Zoom bug can let hackers steal your Windows password
Apr 2, 2020 8:10 AM

Slammed for the lack of users privacy and security by the US Federal Bureau of Investigation (FBI) and cybersecurity experts, video meeting app Zoom is also prone to hacking, a new report has claimed, saying an unpatched bug can let hackers steal users Windows password.

The 'Zoom client for Windows' is vulnerable to the 'UNC path injection' vulnerability that could let remote attackers steal login credentials for victims' Windows systems, reports TheHacckeNews.

The latest finding by cybersecurity expert @_g0dmode, has also been "confirmed by researcher Matthew Hickey and Mohamed A. Baset,' the report said late Wednesday.

The attack involves the "SMBRelay technique" wherein Windows automatically exposes a user's login username and NTLM password hashes to a remote server, when attempting to connect and download a file hosted on it.

"The attack is possible only because Zoom for Windows supports remote UNC paths, which converts such potentially insecure URLs into hyperlinks for recipients in a personal or group chat," the report claimed.

Besides Windows credentials, the vulnerability can also be exploited to launch any programme present on a targeted computer.

Zoom has been notified of this bug but the flaw is yet to be fixed.

"Users are advised to either use an alternative video conferencing software or Zoom in your web browser instead of the dedicated client app," said the report.

Another media report claimed that Zoom doesn't use end-to-end encryption to protect calling data of its users.

As businesses, schools and colleges and millions of SMBs use video conferencing tool Zoom during the work-from-home scenario, the US Federal Bureau of Investigation (FBI) has warned people about porn material being popped up during the video meetings.

The Boston branch of the law enforcement agency said it has received multiple reports of Zoom conferences being disrupted by pornographic and/or hate images and threatening language.

The video conferencing app late last month updated its iOS app to remove the software development kit (SDK) that was providing users' data to Facebook through the Login with Facebook feature.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Check Out What Whales Are Doing With ASML
Check Out What Whales Are Doing With ASML
Jun 7, 2024
Deep-pocketed investors have adopted a bullish approach towards ASML Holding ( ASML ) , and it's something market players shouldn't ignore. Our tracking of public options records at Benzinga unveiled this significant move today. The identity of these investors remains unknown, but such a substantial move in ASML ( ASML ) usually suggests something big is about to happen. We...
The AUDUSD price forecast update 07-06-2024
The AUDUSD price forecast update 07-06-2024
Jun 7, 2024
The AUDUSD price broke 0.6640$ level strongly to turn to decline for the rest of the day, paving the way to achieve negative targets that start at 0.6570$, noting that breaching 0.6640$ will stop the current negative pressure and lead the price to recover again. The expected trading range for today is between 0.6580$ support and 0.6650$ resistance Trend forecast:...
Gold price forecast update 07-06-2024
Gold price forecast update 07-06-2024
Jun 7, 2024
Gold price broke 2340.10$ level to open the way to return to the correctional bearish track, and we suggest targeting 2272.06$ areas as a next negative station, making the bearish bias suggested in the upcoming sessions, noting that breaching 2340.10$ and holding above it again will reactivate the bullish wave that its first target located at 2400.00$. The expected trading...
End of day EURUSD price forecast update - 07-06-2024
End of day EURUSD price forecast update - 07-06-2024
Jun 7, 2024
The EURUSD price declines strongly to break 1.0840$ level and attempt to hold below it, to head towards turning to decline for the rest of the day, paving the way to achieve negative targets that start at 1.0795$ and extend to 1.0760$, taking into consideration that breaching 1.0840$ and holding above it will stop the expected decline and lead the...
Copyright 2023-2026 - www.financetom.com All Rights Reserved