资安公司 A Security 的研究人员在 6 月初利用公开的 AI 模型,仅用了不到 20 次的提示,就在 Zoom 的视讯会议软体中发现了严重的漏洞,并成功开发出攻击手法。
这些漏洞存在于 Zoom 萤幕分享时的即时注记功能协定中。只要参与含有萤幕分享的视讯通话,无论是主办人还是与会者,都可能在毫无察觉且无需任何互动的情况下遭到攻击,甚至导致设备被完全控制。
Zoom 已在周二发布了安全公告,并开始针对所有支援的作业系统(包括 Windows、macOS、Linux、iOS 和 Android)推出伺服器端和客户端修补程式以解决此问题。
Researchers from the cybersecurity firm A Security discovered severe vulnerabilities in the Zoom video conferencing software in early June by using publicly available AI models, developing a successful attack with fewer than 20 prompts.
The vulnerabilities were located in the protocol used for real-time annotation during screen sharing. Anyone participating in a call involving screen sharing, whether host or participant, could be attacked silently without any indication or interaction, potentially leading to complete device takeover.
Zoom issued a security advisory on Tuesday and has begun rolling out server-side and client-side patches for all supported operating systems, including Windows, macOS, Linux, iOS, and Android, to address the flaws.