Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

In Defense of Zoom

Edgescan’s Senior Security Consultant, Guram Javakhishvili, gives his take on the Zoom debacle

by The Gurus
April 17, 2020
in Featured, News
edgescan logo
Share on FacebookShare on Twitter

Guram stresses that he is not ‘sponsored by Zoom’ 😊

First of all, nothing is bulletproof and anything can be hacked. We all make mistakes and learn from them. That’s how and why we improve and update software on a regular basis.

Question is: on what basis are other blog posters or researchers assuming that there’s RCE, UNC Path Injection, weak or no E2E encryption and many other vulnerabilities which have been mentioned over the past few weeks? If they have been testing or targeting Zoom systems in its production environment without penetration testing authorisation then that is illegal and unethical. I believe most of these blog posts are just repeating unethical researchers unauthorised publications.

A brief clarification on a few of the vulnerabilities recently posted and my personal thoughts on them:

  1. Zoom video recordings accessible to the public

This is a user issue. There is an option within the Zoom admin panel where you can set video records to be private, public or only accessible by call participants. If you are not aware of current settings, better check before recording. If recording is set to ‘Public’ then anyone with access to the link will be able to see the video content.

By default, users tend to leave ‘Public’ enabled and then if they post the link somewhere or even access the link through the shared browser (since the encrypted key of the video record is contained in URL) it will stay in browser history and whoever has access to the machine will be able to access it.

  1. Zoom bombing (attackers can brute force ID and Password)

Even if you had valid password and ID, you still start a call in a ‘waiting room’ until host admits you. You can basically do nothing in the waiting room, and there is no way you can bypass until the host admits you to the meeting.

Also, I’m not too sure about brute-forcing since Zoom uses WAF protection Cloudflare. This needs a little bit of tuning (I would have thought, Zoom allowed multiple failed login attempts without blocking joiners, since participants might get password or id wrong) but again this can be enhanced from admin panel if one is familiar with the settings.

Again, user awareness – choose to use complex passwords, you can always set this yourself if you wanted to be safe.

  1. UNC Path Injection

UNC Path is possible with other modern applications too, not just Zoom. MS Outlook does also allow UNC Path as hyperlink. So what? We have never abandoned Outlook for this. Nevertheless, Zoom already addressed this and latest release does not allow UNC Path anymore.

  1. Zoom does not support E2E Encryption

Zoom acknowledges encryption problems and they proactively worked on this to address E2E encryption issues. Zoom indeed always supported TLSv1.2 for all its communications but there was a weak cryptographic cipher. A single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption.

It should be mentioned that even if third-party deliberately disables E2E encryption and initiates a meeting but then if guest joins with E2E encryption enabled then this feature gets enforced and communication for both parties become encrypted.

  1. Inconsistent Application of Security Policy

Advice to Zoom team and Zoom users on anomalies with file sharing, recording and, screenshare and remote controlling:

  • File Sharing

File share can be disabled from Zoom admin panel and people from your organisation will not be able to transfer files during Zoom chat/meetings. However, if a third-party host has this function enabled, it is possible to send files to all participant users (guests). If participants have file share disabled by their Admin and they can’t send files, they will still be able to receive and download files from third-party host, which increases the risk of being sent malware or other malicious files.

  • Recording

If the Recording feature is disabled from your organisation’s Zoom Admin, and someone from your organisation is hosting a meeting, the recording feature will not be available for any party, including third-parties. However, if a third-party host has this function enabled, then this function is available for all meeting participants (your organisation and third-party).

  • Screenshare + Remote Controlling

I would recommend reviewing the use of this function and disabling if not required.

By default, ‘Remote Control’ feature is not disabled and locked by administrators. Enabling Remote Control function for your organisation’s participants or host users increases the risk of your members permitting third-parties to potentially take remote control over an internal host system and possibly accessing unintended information or your organisation’s network resources.

It should be noted that an end-user must still grant permission to allow remote controlling of their system.

In summary

Most importantly, testing or using third-party software unethically is illegal and authorisation should be sought prior to any activity. EternalBlue targeted thousands of Windows systems and more than 200K organisations suffered as a result of EternalBlue vulnerability but no one abandoned Windows systems and still use it. Whatsapp also suffered from some serious vulnerabilities but we still use them. As long as Zoom is taking actions on all security concerns and tries to resolve issues as soon as possible, that’s the main thing.

Zoom free version comes with limited administrative access and might not give you full control over security controls and settings. If you choose to use a free licence you accept that it will not have the full range of features as the paid version.  If you want those features, pay for them.

Review your Zoom admin panel settings thoroughly and ensure you understand what is what and what does what.

You can read more about the security of collaboration apps here.

 

ShareTweet
Previous Post

Portuguese energy giant EDP being held to ransom after malware attack

Next Post

Hackers linked to Syrian government target civilians with spyware via mobile apps  

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol