Zoom Patches Chat Flaw That Exposes Windows Passwords to Hackers
Zoom automatically pushes a fix for a vulnerability that allows attackers to steal Windows credentials through malicious chat links. The company promises increased transparency as security experts continue to scrutinize the popular video conferencing software.
A recently discovered vulnerability in Zoom allows hackers to steal Windows credentials simply by sending a malicious link in the chat window. This attack, known as a UNC path injection, tricks Windows into exposing a user's encrypted login name and password to a remote server when the link is clicked. Security researchers note that third-party tools can easily decrypt these credentials if the user relies on a weak password.
Zoom responds quickly to this threat by automatically pushing out a patch to its user base, bringing the software up to version 4.6.9. The company's CEO addresses the issue in a public blog post, detailing the fix alongside promises of better transparency moving forward. Until the automatic update reaches all users, security experts recommend either disabling the automatic transmission of NTLM credentials in Windows security policies or accessing Zoom exclusively through a web browser.
This credential theft flaw emerges as part of a broader wave of security scrutiny surrounding the rapidly growing video conferencing platform. In addition to the threat of unauthorized "Zoom bombing," the company faces heavy criticism for misleadingly marketing its calls as end-to-end encrypted. Previous vulnerabilities, including a flaw that allowed remote attackers to activate a Mac user's camera without permission, highlight the ongoing security challenges Zoom faces as its popularity surges.