Security News

Zoom bug let users watch meetings in waiting room

A security vulnerability in videoconferencing software Zoom made it possible for users who were not yet admitted to a meeting to watch anyway. Zoom offers a “waiting room”, where all persons who want to participate in a meeting can be accommodated. The host of the meeting can then give people in the waiting room access to the meeting. This should prevent direct access to the meeting.

It turned out that the Zoom servers automatically sent a live video stream of the meeting, as well as the decryption key of the meeting, to all users in the waiting room. They would be able to watch the meeting, even if the host had not given permission for this. Zoom recommends the use of the waiting room to prevent abuse such as Zoom-bombing. The audio stream of the meeting was not sent to people in the waiting room.

Researchers from Citizen Lab, a laboratory that is part of the University of Toronto, discovered the vulnerability and reported it to Zoom at the beginning of April. On April 7, Zoom performed a security update on its own servers, which solved the vulnerability. As a result, Citizen Lab has now made the details of the security breach public.

Earlier, Citizen Lab published an extensive report about all kinds of problems with Zoom, including the encryption used and the fact that encryption keys of non-Chinese users were sent to Chinese servers. In addition, it appears that Zoom, an American company, owns three Chinese companies of around 700 employees, who are paid to develop the Zoom software. In the meantime, Zoom has stopped using Chinese servers for non-Chinese users. In addition, the company says it will implement end-to-end encryption, but this may still take months.

Max Reisler

Greetings! I'm Max, part of our malware removal team. Our mission is to stay vigilant against evolving malware threats. Through our blog, we keep you updated on the latest malware and computer virus dangers, equipping you with the tools to safeguard your devices. Your support in spreading this valuable information across social media is invaluable in our collective effort to protect others.

Recent Posts

Remove BAAA ransomware (Decrypt BAAA files)

Every passing day makes ransomware attacks more normal. They create havoc and demand a monetary…

11 hours ago

Remove Wifebaabuy.live (virus removal guide)

Many individuals report facing issue­s with a website called Wifebaabuy.live. This we­bsite tricks users into…

1 day ago

Remove OpenProcess (Mac OS X) virus

Cyber threats, like unwanted software installations, come in many shapes and sizes. Adware, especially ones…

1 day ago

Remove Typeinitiator.gpa (Mac OS X) virus

Cyber threats, like unwanted software installations, come in many shapes and sizes. Adware, especially ones…

1 day ago

Remove Colorattaches.com (virus removal guide)

Many individuals report facing issue­s with a website called Colorattaches.com. This we­bsite tricks users into…

1 day ago

Remove ProjectRootEducate (Mac OS X) virus

Cyber threats, like unwanted software installations, come in many shapes and sizes. Adware, especially ones…

1 day ago