Unauthorized Call and Webcam Access Vulnerability in Zoom Mac Client (CVE-2019-13450)

Ryan Seguin

A zero-day vulnerability in Zoom could potentially lead to a remote code execution attack. Here’s what you need to know.

Background

Security researcher Jonathan Leitschuh has disclosed a zero day in the Zoom client for Mac, that allows an attacker to force a user to join a Zoom call with their webcam enabled. The disclosure blog also suggests this could potentially lead to a remote code execution attack (RCE), which may have been found by other researchers as well but remains undisclosed and unconfirmed. According to the research, a web server running on port 19421 is present if the Zoom client on Mac has ever been installed.

Analysis

Malicious HTTP requests can be sent to the web server installed alongside the Zoom Mac client that launches a video call with the attacker, with the affected user’s webcam enabled. These requests cannot override user configuration though, so if a user has disabled the automatic webcam, they may still be joined to a call, but their webcam will not be enabled. The researcher also mentions CVE-2018-15715, a Zoom message spoofing flaw discovered by Tenable researcher David Wells, which could be used in conjunction with CVE-2019-13450 to execute an RCE attack.

Proof of concept

The advisory blog provides the following lines of code that an attacker could embed in their site to initiate a call with a vulnerable user:

And the following line enables the webcam for users with automatic video turned on:

Vendor response

Zoom has responded to the disclosure with additional information on how it’s going to improve the user experience to alleviate concerns in the future. Zoom also noted that the Denial of Service (DoS) vulnerability reported by the researcher (CVE-2019-13449) was fixed in May 2019 (Client version 4.4.2).

Solution

Zoom has released an update for the Mac client (4.4.53932.0709) that removes the web server and allows users to fully uninstall Zoom from the client. That update can be applied from the Zoom client or downloaded manually here. Zoom has also stated that it plans to provide further updates over the course of the coming weekend (July 12).

Users can disable automatic video in Zoom, which can be found here in your user settings:

How to disable automatic video in Zoom

Image Source: Jonathan Leitschuh

Identifying affected systems

A list of Nessus plugins to identify this vulnerability will appear here as they’re released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io.

Read more >

Published on Jul 10, 2019

People also viewed

Enterprise Territory Manager - Chicago

Chicago Illinois United States Chicago, Illinois, United States Sales Sales
Your Role:Tenable is currently searching for an Enterprise Territory Manager. The Enterprise Territory Manager (ETM) is responsible for establishing and developing business through existing and new clients in an assigned territory.Your Opportunity...

Enterprise Territory Manager - Chicago

Milwaukee Wisconsin United States Milwaukee, Wisconsin, United States Sales Sales
Your Role:Tenable is currently searching for an Enterprise Territory Manager. The Enterprise Territory Manager (ETM) is responsible for establishing and developing business through existing and new clients in an assigned territory.Your Opportunity...

Software Engineer - Web Scraping (Python)

Remote United States Remote, United States, 97458 Research Engineering
Your Role:Tenable is looking for a Software Engineer to join our Automation research team.  This position will involve building and maintaining our framework for automated content creation, validation, and deliveryYour Opportunity: Impact: You wi...

Product Security Architect - Security Development Lifecycle

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 21046 Information Security IT
Your Role:As part of the Information Security team, the Principal Product Security Architect will help drive and coordinate security for Tenable’s applications and services portfolio. This includes designing and working on Security Development Lif...

Software Engineer

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 21046 Engineering Engineering
Your Role:Are you excited about the opportunity to work with microservices at scale? Do you like knowing that the changes that you deploy to production will improve the customer experience of many users worldwide? Do you like both the exciting, fa...

Software Engineering Manager, UI

San Jose California United States E Santa Clara St., San Jose, California, United States, 95113 Engineering Engineering
Your Role:Tenable is looking for an extraordinary Engineering Manager to join the Tenable.io Engineering team. This is an opportunity to make a high impact while helping the team deliver on a next-generation enterprise web application. The ideal c...

We have big plans for continued global growth, and we’re looking for people who are creative, flexible and dedicated to helping us build something great – something that matters.