Skip to main content

Posts

Showing posts with the label Zoom for Windows puts user credentials at risk

Zoom for Windows puts user credentials at risk

Zoom video conferencing software for Windows is vulnerable to a classic 'UNC path injection' vulnerability that could allow remote attackers to steal victims' Windows login credentials and even execute arbitrary commands on their systems.   The video conferencing app Zoom as recently risen in popularity with people being forced to work from home. Its 100-participant limit and live file collaboration, make it one of the best video conferencing apps out there for work. According to cybersecurity expert @_g0dmode, the Zoom video conferencing software for Windows is vulnerable to a classic 'UNC path injection' vulnerability that could allow remote attackers to steal victims' Windows login credentials and even execute arbitrary commands on their systems. UNC or Universal Naming Convention is a filename format that is used to specify the location of files, folders, and resources on a local-area network. The Zoom Windows client vulnerability lets attackers steal the Wi...