Zoom zero-day discovery
blog.malwarebytes.com
Zoom zero-day discovery
1–10 of 246 posts
Re: Zoom zero-day discovery
#2Critical Zoom vulnerability triggers remote code execution without user input
https://www.zdnet.com/article/critical-zoom-vulnerability-tr...
Re: Zoom zero-day discovery
#3Re: Zoom zero-day discovery
#4Re: Zoom zero-day discovery
#5Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.
Re: Zoom zero-day discovery
#6These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerability across the entire app, or better yet, the whole industry via a research paper.
Re: Zoom zero-day discovery
#7What percentage of these kind of exploits does hn think are found by these kind of white hat exercises and what percentage are sitting out there in an intelligence service or private entity's 0-day database? I have always been curious.
Re: Zoom zero-day discovery
#8“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…
Re: Zoom zero-day discovery
#9Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.
Re: Zoom zero-day discovery
#10Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.
For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.