News April 9th 2021

White hat hackers found massive security flaw in Zoom

April 9th 2021

In the hacking competition Pwn2Own, which is taking place in Vancouver, Canada, two hackers managed to expose Zoom vulnerabilities, showing security flaws in the web conferencing tool. The two Dutchmen ended up winning a prize of US$ 200 thousand for their feat, that is, they will share more than R$ 1,1 million.

A Zero Day Initiative, responsible for the event that challenge hackers finding serious new vulnerabilities in commonly used software and mobile devices, posted a gif on Twitter showing the bug in action.

The post shows the attacker opening the calculator on the system running Zoom. Calc.exe is often used as the program that hackers open on a remote system to show that they can execute code on the affected machine.

The remote code execution (RCE) flaw allowed the “malicious actor” to remotely execute code through Zoom, both the Windows and Mac versions. The tool’s Android app and the iOS – but obviously the flaw means that chat partners on mobile apps could be compromised.

The details of the procedures carried out by Keuper and Alkemade, the two experts who exposed the Zoom security flaw, have been kept confidential. This information will remain undisclosed for 90 days, which is the time given for Zoom to release a security patch focused on the vulnerability found. After this period, the details of the procedures should be released.

Event focused on home-office tools

In the 2021 edition, Pwn2Own focused on software and devices used to work from home, including, in addition to Zoom, Microsoft Teams. The event, which presents an updated theme as it is held, arrived in its 14th year in a remote format, due to the pandemic, and geared towards the current context. According to the initiative's publication, "As the workforce leaves the office and goes remote, the tools needed to support this change become bigger targets."

Interested companies volunteer their software and devices, as well as a reward for hackers who carry out successful attacks. While the experts are rewarded and take home huge sums of money, companies get to know vulnerabilities that had not been previously identified. This prevents these flaws from being sold and used by criminals.

Hackers had almost complete control over the computer

The hackers who participate in the competition are white hats, people who act ethically and are specialized in penetration testing and other related methodologies. They are the ones who ensure, for example, the security of the information systems of large organizations.

Keuper and Alkemade, the white hats who found Zoom's security flaws, are employees of the cybersecurity firm computer test. They combined three vulnerabilities to take control of a remote system on Wednesday (07/04), the second day of the Pwn2Own event. The vulnerabilities did not require any interaction from the victim, not even a click or the victim exploring an attached file. The hackers only needed to be on a call via Zoom.

According to Keuper, the exploit allowed the attackers to gain control over the entire system, which is very sensitive to the security of the web conferencing tool. The Dutch duo managed to gain almost complete control over the remote computer, demonstrating this with various actions, such as toggling the webcam and microphone, looking at the desktop, reading emails and downloading the victim's browser history.

Also in this edition of Pwn2Own, another ethical hacker broke into Microsoft Teams and, like Keuper and Alkemade, exploited a combination of vulnerabilities to execute arbitrary code. The white hat responsible also earned a $200 bounty for exposing the Microsoft bug.

Through which channels you reach those people, classic and out of the box. Malwarebytes e TechRadar

Image: hapabapa/iStock

Read too