Get a Pentest and security assessment of your IT network.

Cyber Security

Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links

The Zoom Windows client is vulnerable to UNC path injection in the client’s chat feature that could allow attackers to steal the Windows credentials of users who click on the link. Windows will send the user’s login name and their NTLM password hash, which can be cracked using free tools like Hashcat to reveal, or reveal, the password. In addition to the stealing of Windows credentials, the UNC injects can also be used to launch programs on a local computer when a link is clicked. Zoom has released version 4.6.6253 of their client that now prevents ALL posted links from being converted into clickable hyperlinks.

Source: https://www.bleepingcomputer.com/news/security/zoom-lets-attackers-steal-windows-credentials-run-programs-via-unc-links/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security