Zoom Ô¶³Ì´úÂëÖ´ÐÐ0 day·ì϶
°ä²¼¹¦·ò 2021-04-120x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-12 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ·ì϶ÏêÇé

Zoom ÊÇÒ»¸öµ¥Ò»Ò×ÓõÄÔÚÏßÊÓÆµ»áÒéÈí¼þ,ËüÌṩÁËÊÓÆµÍ¨Ñ¶¡¢ÒôƵͨѶ¡¢ÆÁÄ»¹²ÏíÂÄÀúÒÔ¼°ÔÚÏßȺ×é̸ÌìÖ°ÄÜ¡£¡£¡£¡£¡£
Pwn2Own½ÏÁ¿ÊÇÓɰ×Ã±ÍøÂ簲ȫרҵÈËÔ±ºÍÍŶӲÎÓ룬£¬£¬£¬£¬£¬£¬£¬ÒÔ¾ºÕù·¢ÏÖÊ¢ÐÐÈí¼þºÍ·þÎñÖеÄÃýÎóµÄ½ÏÁ¿¡£¡£¡£¡£¡£
2021Äê04ÔÂ07ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Á½ÃûºÉÀ¼°×ñ°²È«×¨¼ÒÔÚ²ÎÓëÄê¶ÈÍÆËã»úºÚ¿Í´óÈüPwn2OwnʱÔÚZoomÖз¢ÏÖÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬´Ë·ì϶½áºÏÁËÈý¸ö·ì϶¹¥»÷Á´À´½ÚÔìÔ¶³Ìϵͳ£¬£¬£¬£¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚLAN¡¢WAN»òInternetÉϵÄÔ¶³ÌÍÆËã»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶µÄÀûÓÃÖ»ÐèÓû§½øÐÐÒ»´ÎZoomͨ»°£¬£¬£¬£¬£¬£¬£¬£¬¶øÎÞÐèÓû§½»»¥¡£¡£¡£¡£¡£
Pwn2Own×éÖ¯ÒѾÔÚtwitterÉϰ䲼Á˸÷ì϶µÄgifÀûÓÃÑÝʾ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÔÚÔËÐÐZoomµÄϵͳÉÏ´ò¿ªÍÆËãÆ÷Calc.exe¡£¡£¡£¡£¡£

Ó°ÏìÁìÓò
Windows°æZoom
Mac°æZoom
£¨iOS¼°AndroidĿǰÉÐδ²âÊÔ£¬£¬£¬£¬£¬£¬£¬£¬ä¯ÀÀÆ÷°æ²»ÊÜÓ°Ïì¡£¡£¡£¡£¡££©
0x02 ´ëÖý¨Òé
ÓÉÓÚZoom»¹Ã»Óй¦·ò½¨¸´´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶µÄ¾ßÌå¼¼Êõϸ½ÚÈÔÔÚ±£ÃÜÖС£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÁ½Ãû°²È«×¨¼ÒºÍZoom֪·¸Ã·ì϶µÄ¹¤×÷µÀÀí£¬£¬£¬£¬£¬£¬£¬£¬½¨Ò鹨עZoom¹Ù·½°ä²¼µÄ°²È«¸üС£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.zoom.us/download
0x03 ²Î¿¼Á´½Ó
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/04/zoom-zero-day-discovery-makes-calls-safer-hackers-200000-richer/
https://www.zdnet.com/article/critical-zoom-vulnerability-triggers-remote-code-execution-without-user-input/#ftag=RSSbaffb68
https://twitter.com/i/status/1379855435730149378
0x04 ¹¦·òÏß
2021-04-07 KeuperºÍAlkemade·¢ÏÖ·ì϶
2021-04-12 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ