HT TECH wants to start sending you push notifications. Click allow to subscribe

Zoom resolves security issue that could be exploited to manipulate meeting IDs

This issue, if left as is, would have allowed a hacker to manipulate meeting IDs by posing as an employee of a potential victim organisation on Zoom.

By: HT TECH
Updated on: Aug 20 2022, 22:02 IST
The hacker would begin by introducing themselves as legitimate employees of a company and send an invitation to from an organisation’s Vanity URL to relevant users to gain credibility. (REUTERS)

Zoom and researchers at Check Point worked together to identify a security issue in Zoom’s customisable URL feature. This issue, if left as is, would have allowed a hacker to manipulate meeting IDs by posing as an employee of a potential victim organisation on Zoom giving the hacker a vector for stealing credentials and sensitive information.

Zoom explained that a Vanity URL is the custom URL for a company, for example, yourcompany.zoom.us, and this vanity URL is needed for configuration if you want to turn on SSO (Sing Sign On).

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,990
Check details
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,380₹51,990
Buy now
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999
Check details
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,674₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

Users can also brand this vanity page with a customised logo/branding and generally your end users don’t get any access to this vanity page - they just click on the link to join a meeting here.

The security issue Zoom and Check Point fixed could have been exploited in two ways. One, a hacker could have manipulated the Vanity URL by targeting via direct links. While setting up a meeting the hacker could have changed the URL invitation to include a registered sub-domain of their choice. For example, if the original link was https://zoom.us/j/##########, the attacker could change it to https://<organization’s name>.zoom.us/j/##########.

Without particular cybersecurity training on how to recognise the appropriate URL, a normal user receiving this invitation would not have been able to recognise that the invitation was not genuine or issued from an actual or real organisation or not.

The second way to exploit this security issue is by targeting dedicated Zoom interfaces. Some organisations have their own Zoom interface for conferences. A hacker could target this interface and attempt to redirect a user to enter a meeting ID into the malicious Vanity URL instead of the genuine Zoom interface. Again, like with direct links, most people will not be able to recognise a malicious URL from a genuine one without appropriate training.

The hacker would begin by introducing themselves as legitimate employees of a company and send an invitation to from an organisation’s Vanity URL to relevant users to gain credibility. Finally, when the user fell for the malicious URL, the hacker could steal credentials and sensitive information. 

The issue has been fixed, so you can Zoom in peace now.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 16 Jul, 18:28 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,590₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
13% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,058₹101,398
Buy now
29% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,990₹44,999
Buy now
28% OFF
Asus TUF Dash F15 FX517ZR HQ030WS Laptop
  • Black
  • 16 GB RAM
  • 1 TB SSD
₹55,990₹77,990
Buy now
41% OFF
MSI Modern 14 C12M 671IN Laptop
  • Urban Silver
  • 16 GB RAM
  • 512 GB SSD
₹32,490₹54,990
Buy now
31% OFF
Asus Zenbook 14 Flip OLED UP3404VA KN542WS Laptop
  • Ponder Blue
  • 16 GB RAM
  • 512 GB SSD
₹67,990₹98,990
Buy now
NEXT ARTICLE BEGINS