一个Zoom屏幕共享漏洞曾允许任何人接管通话中的其他设备。

内容来源:https://www.wired.com/story/a-zoom-screen-sharing-bug-let-anyone-take-over-other-devices-on-a-call/
内容总结:
AI“闪电”破防Zoom:20条提示词找出致命漏洞,一键接管用户设备
本周二,网络安全研究人员公布了一项令人警醒的发现:全球广泛使用的视频会议平台Zoom存在严重安全漏洞,攻击者可利用该漏洞在无需任何用户交互的情况下,静默接管目标设备。这意味着,任何参与屏幕共享通话的人,无论是主持人还是普通与会者,都可能沦为“沉默攻击”的受害者。
该漏洞由数字防御公司A Security的研究团队发现。值得注意的是,这次漏洞挖掘并非依靠传统人工,而是借助了公开可用的AI模型。研究人员表示,他们仅用不到20条提示词,就成功定位漏洞并构建出可用的攻击代码,整个过程高效得令人咋舌。A Security联合创始人奥默·古尔指出,这一发现最危险之处在于“能力的普及化”——“过去可能需要一个五人团队花费六个月时间反复打磨才能找到的漏洞,现在人们用不到20条提示词就能达到同样结果。”
据悉,此次漏洞主要存在于Zoom屏幕共享功能中用于实现实时注解的协议组件内。研究人员解释,AI系统之所以精准“盯上”这一模块,是因为其代码逻辑复杂且不透明,如同人类安全专家一样,AI也“学”会了在看似晦涩的角落中寻找被忽视的破绽。对于Zoom这类闭源商业软件,尽管公司理应进行严格的代码审查,但缺乏开源社区的公开监督,此类功能复杂的冷门模块仍是漏洞的高发区。
针对该发现,Zoom已于周二发布安全公告,并开始逐步推送服务器端和客户端修复补丁,以覆盖其支持的所有操作系统,包括Windows、macOS、Linux、iOS和Android。但A Security联合创始人约西·托拉蒂警告说,该漏洞的潜在破坏力极其惊人:“只要和你进入同一个Zoom会议,我们就能控制你的设备。最坏的情况下,攻击者能借此攻陷整个企业——控制员工的电脑和凭证,然后在企业内部网络中横向移动。”
安全专家坦言,网络安全常被比作“猫鼠游戏”,但随着AI驱动的漏洞挖掘技术快速普及,这场攻防博弈已演变为一场争分夺秒的全面竞赛。
中文翻译:
随着人工智能模型在发现软件漏洞、开发利用这些漏洞的方法,甚至实施自主黑客攻击方面能力不断增强,研究人员周二给出了一个发人深省的新例证,披露了视频会议平台Zoom中可能被利用来接管目标设备的漏洞。任何参与涉及屏幕共享的通话的人,无论是参与者还是主持人,都可能遭受无声攻击,这种攻击无需任何提示,也无需受害者进行任何交互即可实施。
来自数字防御公司A Security的研究人员表示,该漏洞于6月初使用公开可用的人工智能模型被发现,仅用不到20个提示词就找到了这些漏洞并创建了可行的攻击方案。Zoom周二发布了安全公告,包括公司已开始推出的修复措施详情,这些漏洞影响了运行Zoom支持的所有操作系统(Windows、macOS、Linux、iOS和Android)的设备。
“在我们看来有趣且危险的是这些能力的普及化——进入门槛正在迅速降低,”A Security联合创始人Omer Gull在披露前告诉《连线》杂志。“以前这需要一支五人团队花费大约六个月时间,经过大量优化和迭代才能发现。现在人们用不到20个提示词就能达到同样的结果。而Zoom是一个重要的目标类型,因为人们在使用它时抱有信任。他们不认为它是一种威胁。”
这些漏洞具体存在于用于屏幕共享期间实时标注的协议中。研究人员表示,他们的人工智能漏洞狩猎系统之所以专门深入调查这个组件,是因为与人漏洞猎手一样,他们被训练认识到复杂且隐蔽的功能往往包含被忽视的漏洞。这在专有、闭源软件中尤其如此。像Zoom这样的老牌公司理应对所有组件和功能进行广泛的代码审查和验证,但没有公开开源审查的益处,像标注这样深奥而复杂的功能更有可能包含错误。
Zoom未回应《连线》杂志就A Security的发现提出的多次置评请求。
这些漏洞现已修补,Zoom同时发布了服务器端和客户端修复——即对Zoom自有服务器和客户设备上运行的应用程序的补丁。但研究人员强调,想到只需要让人加入一个Zoom通话就可能利用这些漏洞接管目标设备,令人震惊。加入通话本身就是一种信任的姿态,但鉴于视频通话在个人和专业场景中都无处不在——而且尤其考虑到Zoom也被广泛用于活动和网络研讨会等半公开活动——人们加入Zoom时通常会放松警惕。
“只要你和我们加入一个Zoom通话,我们就能接管你的设备,”A Security联合创始人Yossi Torati在通话中告诉《连线》杂志。(顺便提一句,这次通话是在Microsoft Teams上进行的。)“最坏的情况是,我们只需要掌握这个漏洞就能接管一家企业。如果我是攻击者,我可以与公司某人在一个通话中,控制他们的电脑和凭据,然后利用这些信息在企业内部进行横向移动。”
从业者常称安全为一场“猫鼠游戏”,但随着人工智能漏洞狩猎的普及,这种微妙的博弈已演变为一场全面竞赛。
评论
返回顶部
英文来源:
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.
Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.
“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”
The vulnerabilities were specifically in the protocol used to facilitate real-time annotation during screen sharing. The researchers say that their AI bug hunting systems specifically delved into this component because, like human bug hunters, they have been trained that convoluted and obscure functions often contain overlooked vulnerabilities. This is particularly true with proprietary, closed-source software. An established company like Zoom presumably does extensive code review and vetting on all components and functions, but without the benefit of public, open review, esoteric yet complex features like annotation are more likely to contain mistakes.
Zoom did not respond to multiple requests for comment from WIRED about the A Security findings.
The bugs are now patched, with Zoom issuing both server and client-side fixes—or patches for both Zoom’s own servers and the applications that run on customer devices. But the researchers emphasize that it was alarming to contemplate bugs that could have been exploited to take over a target device simply by getting someone onto a Zoom call. Joining a call is in itself a gesture of trust, but given how ubiquitous video calling is in both personal and professional contexts—and given that Zoom in particular is also widely used for events and semipublic activities like webinars—people typically have their guard down when joining a Zoom.
“If you just get on a Zoom with us, we can take over your device,” A Security cofounder Yossi Torati told WIRED on a call. (It was, incidentally, hosted on Microsoft Teams.) “The worst-case scenario is that we can take over an enterprise just by having this vulnerability in our hands. If I’m an attacker, I can be on a call with someone from a company, take control of their computer and their credentials, and then use them to move laterally in the enterprise.”
Practitioners often call security a “cat-and-mouse game,” but as AI bug hunting proliferates, this delicate dance has become an all-out race.
Comments
Back to top
文章标题:一个Zoom屏幕共享漏洞曾允许任何人接管通话中的其他设备。
文章链接:https://news.qimuai.cn/?post=4781
本站文章均为原创,未经授权请勿用于任何商业用途