London Daily

Focus on the big picture.
Monday, Oct 05, 2026

Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links

Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links

The Zoom Windows client is vulnerable to UNC path injection in the client's chat feature that could allow attackers to steal the Windows credentials of users who click on the link.

The zero-day Zoom flaws could give local, unprivileged attackers root privileges, and allow them to access victims’ microphone and camera.

Two zero-day flaws have been uncovered in Zoom’s macOS client version, according to researchers. The web conferencing platform vulnerabilities could give local, unprivileged attackers root privileges, and allow them to access victims’ microphone and camera.

The two flaws, uncovered by Patrick Wardle, principle security researcher with Jamf, emerge as Zoom comes under increased scrutiny over its security measures, particularly with more employees working from home over the past few weeks due to the coronavirus pandemic.

“Today, we uncovered two (local) security issues affecting Zoom’s macOS application,” said Wardle in a post this week. “Given Zoom’s privacy and security track record this should surprise absolutely zero people.”

The vulnerabilities come with the caveat that an attacker needs a local foothold on systems to exploit them – so bad actors would first need physical access to a victims’ computer. Another attack scenario could include a post-malware infection attack by a remote adversary with a preexisting foothold on the targeted system.

The first flaw stems from an issue with Zoom’s installer and allows unprivileged attackers to gain root privileges. The issue stems from the Zoom installer using the AuthorizationExecuteWithPrivileges application programming interface (API) function, which is used to install the Zoom MacOS app (leveraging preinstallation scripts) without any user interaction.

The API has actually been deprecated by Apple because the it does not attempt to validate a binary being executed at root. Because Zoom is using this API, it means “a local unprivileged attacker or piece of malware may be able to surreptitiously tamper or replace that item in order to escalate their privileges to root,” said Wardle.

To exploit Zoom, the local, non-privileged attacker could simply modify a binary to include the runwithroot script during an install. Because it would then not be validated they would ultimately gain root access.

The second zero day flaw gives attackers Zoom’s mic and camera access, allowing for a way to record Zoom meetings, or snoop in on victims’ personal lives – sans a user access prompt.

Zoom requires access to a system microphone and camera due to its nature of being a web conferencing platform. While recent versions of macOS require explicit user approval for these permissions, Zoom has an “exception” that allows code to be injected by third party libraries. Wardle said a malicious third party library could be loaded into Zoom’s process/address space – automatically inheriting all Zooms access rights, and ultimately giving attackers control over these camera and microphone permissions.

“Due to an ‘exception’ entitlement, we showed how to inject a malicious library into Zoom’s trusted process context,” Wardle said. “This affords malware the ability to record all Zoom meetings, or, simply spawn Zoom in the background to access the mic and webcam at arbitrary times.”

Wardle said, “the former [flaw] is problematic as many enterprises (now) utilize Zoom for (likely) sensitive business meetings, while the latter is problematic as it affords malware the opportunity to surreptitious access either the mic or the webcam, with no macOS alerts and/or prompts.”



Other Security Flaws

Zoom security issues are snowballing. The FBI on Tuesday warned of multiple reports of conferences being disrupted by pornographic or hate images and threatening language, in so-called “Zoom-bombing” attacks. These include a Massachusetts high school online classroom using Zoom, where an unidentified individual dialed in, yelled a profanity and then shouted the teacher’s home address in the middle of instruction, said the FBI’s report.

On Tuesday, security researchers uncovered a Universal Naming Convention (UNC) path injection vulnerability in the Zoom Windows client, which could enable attackers to steal Windows credentials of users. The flaw was first discovered by a Twitter user under the handle _g0dmode, and then verified by security researcher Matthew Hickey, with cybersecurity firm Hacker House.

In chat messages on its platform, Zoom automatically converts UNC paths into clickable links. A UNC path is a PC format for specifying the location of resources on a local-area network (LAN), which can be used to access network resources.

Once a victim in the chat clicks on the linked UNC path, Windows will attempt to connect to the link using an SMB file sharing protocol, according to a report by Bleeping Computer. By default, this transmits the victim’s login name and password. The password is hashed via NTLM, but can easily be sniffed out and cracked by attackers (using free tools like Hashcat).

A separate Zoom issue, reported Wednesday by Motherboard, shows that Zoom is leaking the email addresses and photos of thousands of users. This is due to an issue in Zoom’s “Company Directory,” where the platform automatically adds people to other’s lists of contacts if they use an email address sharing the same domain.

“By default, your Zoom contacts directory contains internal users in the same organization, who are either on the same account or who’s email address uses the same domain as yours (except for publicly used domains including gmail.com, yahoo.com, hotmail.com, etc) in the Company Directory section,” according to Zoom’s support page.
Newsletter

Related Articles

0:00
0:00
Close
BT Accused of Pressuring Vulnerable Customers During Digital Landline Shift
British Carmakers Warn of Growing Pressure From EU-China Tariff Dispute
Green Party of England and Wales Adopts Motion Defining Zionism as Racism
Medical Charity Threatens NHS Legal Action Over Two-Year Autism and ADHD Assessment Waits
British Transport Police Report Record Rise in Violence on Railways
Glasgow Council Workers Face Pay Cuts Under Fire-and-Rehire Plan
British Medical Groups Press Prime Minister Andy Burnham to Cancel £330 Million Palantir NHS Contract
UK Faces Record Bluetongue Outbreak Across Livestock Farms
UK Schools Report Thousands of Child-on-Child Sexual Offences
High Court Overturns Ban Blocking Gaza Families From Reuniting With Relatives in UK
G7 Authorizes Emergency Fuel Release as UK Diesel Prices Hit £2 a Litre
France and Italy Draw 1-1 in Nations League Match
Pope Leo XIV and Prince Albert II of Monaco Meet in Metz
SNCF Expands Low-Cost Ouigo High-Speed Service Between Lyon and Bordeaux
Paris Expands Dedicated Cargo Bike Routes for Urban Deliveries
French Film Industry Pushes for Tighter Streaming Investment Rules
Marseille Court Hands Down Prison Terms in Public Procurement Corruption Case
LVMH and Kering Rely on US Demand as Chinese Luxury Spending Slows
Toulouse Aerospace Sector Launches €80 Million Modernization Fund
Javier Milei Courts French Investment in LNG and Lithium
Mistral AI Launches Sovereign Model for European Public Services
French Competition Authority Fines Retailers €40 Million Over Misleading Promotions
France Records Exceptional Electricity Exports as Nuclear Output Recovers
Dassault Aviation Expands Rafale Assembly Capacity at Mérignac
Sanofi Invests €1 Billion in New Biologics Production Hub Near Lyon
France Protests Germany’s Extension of Border Controls Into 2027
French Public-Sector and Transport Unions Threaten National Strike
France Deploys Riot Police After Violence in Lyon Suburbs
French Anti-Terrorism Prosecutors Investigate Radicalized Flydubai Co-Pilot
France’s Defense Budget Surpasses NATO’s 2% of GDP Target
French Government Faces No-Confidence Threat Over Budget
France and G7 Release 100 Million Barrels From Strategic Oil Reserves
France Convenes Emergency Defense Council Over Threats to Commercial Shipping
France and Germany Coordinate Military Response After Russian Strikes on Kyiv Infrastructure
UK Police Release Six Iranian Nationals on Bail After RAF Fairford Security Alert
UK Business Confidence Falls as Energy Costs and Tax Uncertainty Rise
Cornwall Insight Warns UK Energy Bills Could Rise 16% in January
UK Introduces Zero VAT on Household Electricity Bills
UK 30-Year Gilt Yield Hits 6% as Bond Market Pressures Intensify
UK Introduces Stricter Subcontractor Checks and Expanded Trade Union Access
Green Party Proposes Three-Year Emergency Freeze on Private Rent Increases
UK Treasury Committee Seeks Tax Clarification Over Manchester City Investigation
Royal Marines Deploy to Faroe Islands for Northern European Security Exercise
UK Business Confidence Weakens as High Costs Delay Investment
UK GDP Growth Revised Up to 0.5% in Second Quarter
Bank of England Warns of Financial Stability Risks From Autonomous AI
UK Expands Early Prisoner Release Scheme to Ease Overcrowding
UK Records Worst Bluetongue Outbreak on Record Across Livestock Farms
UK Government Faces Shrinking Fiscal Headroom Ahead of October 28 Budget
UK 30-Year Gilt Yield Reaches 6% as Energy Shock Drives Borrowing Costs Higher
×