A message from John Furrier, co-founder of SiliconANGLE:

Zoom Video Communications Inc. today released a patch for a vulnerability disclosed by security researcher Patrick Wardle at the annual DEF CON conference last week.

The vulnerability, named CVE-2022-28756, was found in Zoom for macOS versions 5.7.3 through 5.11.3 and potentially allowed an attacker to gain access to and take over an Apple Inc. computer. using the Zoom package installer. The vulnerability has a Common Vulnerabilities and Exposures score of 8.8, and all Mac Zoom users are encouraged to update to the latest version of Zoom, 5.11.5, as soon as possible.

The exploit lies in the way the Zoom auto-update client connects to a privileged daemon or back-end service. In a rather strange two-step process, someone looking to target a Zoom Mac user could bypass Zoom’s verification checker, tricking the update manager into forcing Zoom to downgrade to an earlier version and more easily Zoom exploit or even force it to download. a completely different package. After exploiting the first stage, the more vulnerable version of Zoom, or a different package, would allow the attacker to gain root access to the victim’s Mac.

“The Zoom client for meetings for macOS (standard and for IT admin) … contains a vulnerability in the automatic update process,” Zoom said in a security bulletin. “A local user with low privileges could exploit this vulnerability to elevate their privileges to root.”

Software vulnerabilities are nothing new, and Zoom has had its fair share in the past, especially when the software went from a semi-obscure offering to becoming a verb for video conferencing as remote working became became the norm during the COVID-19 pandemic. Where this vulnerability exposure becomes particularly interesting is that it was exposed before Zoom had a proper patch available for it.

Typically, when security researchers or so-called “white hat hackers” discover a vulnerability, they contact the company behind the faulty software to allow them to fix the problem before the details of vulnerability. Zoom was made aware of the vulnerability seven months before Wardle made the details public and had plenty of opportunities to properly patch it, but failed to do so.

Mahalo to everyone who came to my @defcon talk “You’re M̶u̶t̶e̶d̶ rooted” 🙏🏽

I was excited to discuss (and live demo 😅) a local priv-esc vulnerability in Zoom (for macOS).

There are currently no patches 👀😱

Slides with full details and exploitation of PoC: #0day pic.twitter.com/9dW7DdUm7P

— patrick wardle (@patrickwardle) August 12, 2022

According to Wardle, as reported by Naked Security for Sophos plc, just before DEF CON, Zoom said it had fixed the vulnerability. However, “after applying the patch, it was noticed that there was still a gap in the update process.” Further patching of the bugfix followed after Wardle’s presentation at DEF CON.

Wardle is well-known in the security community and at every stage did the right thing not only to inform Zoom, but also to try to help it fix the problem. That Zoom took seven months to address a known vulnerability and then release a flawed update doesn’t reflect well.

Image: Zoom

Show your support for our mission by joining our Cube Club and the Cube Event community of experts. Join the community that includes Amazon Web Services and Amazon.com CEO Andy Jassy, ​​Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts

Leave a Comment

Your email address will not be published. Required fields are marked *