Hacking the Pandemic’s Most Popular Software: Zoom

When the pandemic required everyone to work from home we saw a huge growth on the video conferencing market. It was this movement that made the organisation behind the Pwn2Own competition decide to add an ‘Enterprise Communications’ category to this year’s competition. Demonstrating a zero-day attack against the Zoom client would be rewarded with $200,000. We started researching, which resulted in a working exploit against the then latest version of Zoom that would give the attacker full control over your system. Now that Zoom has fixed all the vulnerabilities we found; we can share the details of our research.