A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
Zoom 屏幕共享漏洞允许攻击者接管通话中的设备
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.
随着人工智能模型在发现软件漏洞、开发利用方式甚至进行自主黑客攻击方面展现出更强的能力,研究人员周二提供了一个令人警醒的新案例:他们披露了视频会议平台 Zoom 中存在的漏洞,这些漏洞曾可被利用来接管目标设备。任何参与屏幕共享通话的人,无论是参会者还是主持人,都可能面临这种静默攻击的威胁,且攻击过程无需受害者进行任何交互,也不会留下任何痕迹。
Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.
数字防御公司 A Security 的研究人员表示,该漏洞是于 6 月初利用公开的人工智能模型发现的,仅用了不到 20 条提示词(prompts)就找出了漏洞并创建了有效的攻击方式。Zoom 于周二发布了安全公告,详细说明了公司已开始推出的修复措施,以解决这些影响 Zoom 所支持的所有操作系统(Windows、macOS、Linux、iOS 和 Android)的缺陷。
“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”
“对我们来说,有趣且危险的是这些能力的‘民主化’——进入门槛正在迅速降低,”A Security 联合创始人 Omer Gull 在披露前告诉《连线》(WIRED)杂志。“以前,一个五人团队可能需要六个月的时间,经过大量的改进和迭代才能发现这一点。现在,人们只需不到 20 条提示词就能达到同样的结果。Zoom 是一个重要的目标,因为人们在使用它时会默认信任它,不会将其视为威胁。”
The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes.
这些漏洞存在于屏幕共享期间用于实现实时标注的协议中。研究人员表示,他们的人工智能漏洞挖掘系统专门深入研究了这一组件,因为像人类漏洞猎人一样,它们经过训练,知道复杂且晦涩的功能往往包含被忽视的漏洞。对于专有的闭源软件来说,情况尤其如此。像 Zoom 这样成熟的公司理应会对所有组件和功能进行广泛的代码审查和验证,但在缺乏公开、透明审查的情况下,像标注这样深奥而复杂的功能更容易出现错误。
Zoom did not respond to multiple requests for comment from WIRED about the A Security findings.
对于 A Security 的发现,Zoom 没有回应《连线》杂志多次提出的置评请求。
The bugs are now patched, with Zoom issuing both server and client-side fixes—or patches for both Zoom’s own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. Joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts—and given that Zoom in particular is also widely used for events and semipublic activities like webinars—people typically have their guard down when joining a Zoom.
目前这些漏洞已经修复,Zoom 发布了服务器端和客户端的补丁,即针对 Zoom 自身服务器和运行在客户设备上的应用程序进行了修复。但研究人员强调,仅仅通过让某人加入 Zoom 通话就能接管目标设备,这种漏洞的存在令人担忧。加入通话本身就是一种信任的体现,但考虑到视频通话在个人和职业场景中的普及程度,尤其是 Zoom 还被广泛用于活动和网络研讨会等半公开场合,人们在加入 Zoom 时通常会放松警惕。
“If you just get on a Zoom with us, we can take over your device,” A Security cofounder Yossi Torati told WIRED on a call. (It was, incidentally, hosted on Microsoft Teams.) “The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.”
“如果你只是和我们进行一次 Zoom 通话,我们就能接管你的设备,”A Security 联合创始人 Yossi Torati 在一次通话中告诉《连线》杂志。(顺便提一下,这次通话是在 Microsoft Teams 上进行的。)“最坏的情况是,只要掌握了这个漏洞,我们就能接管整个企业。如果我是攻击者,我可以与某家公司的员工通话,控制他们的电脑和凭据,然后利用这些权限在企业内部进行横向移动。”
Practitioners often call security a “cat-and-mouse game,” but as AI bug hunting proliferates, this delicate dance has become an all-out race.
从业者常将安全称为“猫鼠游戏”,但随着人工智能漏洞挖掘的普及,这场微妙的博弈已演变成一场全方位的竞赛。