Get a Pentest and security assessment of your IT network.

News

Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links

The Zoom Windows client is vulnerable to UNC path injection in the client’s chat feature that could allow attackers to steal the Windows credentials of users who click on the link. Windows will send the user’s login name and their NTLM password hash, which can be cracked using free tools like Hashcat to reveal, or reveal, the password. In addition to the stealing of Windows credentials, the UNC injects can also be used to launch programs on a local computer when a link is clicked. Zoom has released version 4.6.6253 of their client that now prevents ALL posted links from being converted into clickable hyperlinks.

Source: https://www.bleepingcomputer.com/news/security/zoom-lets-attackers-steal-windows-credentials-run-programs-via-unc-links/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

A young hacker violated the CIA Directors private AOL email

News

Facebook Bug #4: Password Reset Vulnerability Found in www.facebook.com