14 total Zoom Vulnerably / Exploit variants and a RCE Remote Code Execution found! Just when you had enough of the first Zoom Vulnerably, Apple released MRTConfigData 1.46 (now 1.47!) to deal with 14 total variants and a Remote Code Execution (RCE).I created this Index of MRT Links & Info to help you get through the confusion. Zoom is the leader in modern enterprise video communications, with an easy, reliable cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems. Zoom Rooms is the original software-based conference room solution used around the world in board, conference, huddle, and training rooms, as well as executive offices and classrooms. Founded in 2011.
Zoomopener
- Report generated: 2019-03-25 09:10:49
- Runtime: 1:35
- Sandbox: Enabled
- Description:
- Anything that appears on this list needs immediate attention.
- No Time Machine backup - Time Machine backup not found.
- Kernel panics - This system has experienced kernel panics that could be related to 3rd party software.
- Minor Issues:
- These issues do not need immediate attention but they may indicate future problems or opportunities for improvement.
- Configuration profiles present - This machine has configuration profiles. These are sometimes used by adware and malware.
- Hardware Information:
- MacBook Pro (13-inch, 2017, Four Thunderbolt 3 ports)
- 1 3.3 GHz Intel Core i5 (i5-7287U) CPU: 2-core
- BANK 0/DIMM0 - 8 GB LPDDR3 2133 ok
- Battery: Health = Normal - Cycle count = 49
- Video Information:
- Color LCD 2880 x 1800
- Drives:
- disk0 - APPLE SSD AP0512J 500.28 GB (Solid State - TRIM: Yes)
- disk0s1 - EFI [EFI] 315 MB
- disk1 [APFS Virtual drive] 499.96 GB (Shared by 4 volumes)
- disk1s2 - Preboot (APFS) [APFS Preboot] (Shared)
- disk1s3 - Recovery (APFS) [Recovery] (Shared - 2.57 GB used)
- disk1s4 - VM (APFS) [APFS VM] (Shared - 3.22 GB used)
- Mounted Volumes:
- APFS
- Encrypted
- disk1s3 - Recovery [Recovery] 499.96 GB (432.91 GB free)
- Mount point: /Volumes/Recovery
- disk1s4 - VM [APFS VM] (Shared - 3.22 GB used)
- Mount point: /private/var/vm
- disk2s1 - A******a 40 MB (33 MB free)
- Disk Image
- Owners enabled: No
- Network:
- Interface en0: Wi-Fi
- Interface en7: Bluetooth PAN
- macOS Mojave 10.14.3 (18D109)
- This computer has configuration profiles installed.
- Notifications:
- /Applications/Microsoft Outlook.app
- /Applications/EtreCheck.app
- Gatekeeper: Enabled
- None
- Kernel Extensions:
- gplock108.kext (4.0.2 - SDK 10.9)
- pangpd_10.9.kext (Palo Alto Networks, 1.0.0 - SDK 10.9)
- /Library/Extensions
- b9kernel.kext (Carbon Black, Inc., 7.2.3.4000 Patch 12 - SDK 10.11)
- CbOsxSensorNetmon.kext (Carbon Black, Inc., 6.2.3.90116 - SDK 10.14)
- CbOsxSensorProcmon.kext (Carbon Black, Inc., 6.2.3.90116 - SDK 10.14)
- /Library/Extensions/CbOsxSensorProcmon.kext/Contents/PlugIns
- cbsystemproxy.kext (Carbon Black, Inc., 6.2.3.90116 - SDK 10.14)
- /Library/Extensions/b9kernel.kext/Contents/PlugIns
- b9kernelkauth.kext (Carbon Black, Inc., 7.2.3.4000 Patch 12 - SDK 10.11)
- b9kernelsupport.kext (Carbon Black, Inc., 7.2.3.4000 Patch 12 - SDK 10.11)
- b9systemproxy.kext (Carbon Black, Inc., 7.2.3.4000 Patch 12 - SDK 10.11)
- System Launch Agents:
- [Loaded] 157 Apple tasks
- [Not Loaded] 33 Apple tasks
- [Running] 134 Apple tasks
- [Running] com.airwatch.mac.agent.plist (Wandering WiFi LLC - installed 2019-03-21)
- [Running] com.bit9.Notifier.plist (Carbon Black, Inc. - installed 2019-01-09)
- [Loaded] com.microsoft.update.agent.plist (Microsoft Corporation - installed 2019-03-14)
- [Running] com.paloaltonetworks.gp.pangpa.plist (? e325755d - installed 2019-03-12)
- [Running] com.paloaltonetworks.gp.pangps.plist (? ce949a03 - installed 2019-03-12)
- [Running] com.spsecure.useragent.plist (Veriato, Inc. - installed 2019-01-09)
- Launch Daemons:
- [Running] com.airwatch.AWRemoteManagementDaemon.plist (Wandering WiFi LLC - installed 2018-10-09)
- [Running] com.airwatch.AWRemoteTunnelAgent.plist (Wandering WiFi LLC - installed 2018-10-09)
- [Loaded] com.airwatch.AWSoftwareUpdateScheduler.plist (Wandering WiFi LLC - installed 2019-03-21)
- [Running] com.airwatch.airwatchd.plist (Wandering WiFi LLC - installed 2018-10-09)
- [Running] com.airwatch.awcmd.plist (Wandering WiFi LLC - installed 2018-10-09)
- [Loaded] com.apple.installer.osmessagetracing.plist (Apple - installed 2019-02-05)
- [Running] com.bit9.Daemon.plist (Carbon Black, Inc. - installed 2019-01-09)
- [Running] com.carbonblack.CbDigitalSignatureHelper.plist (Carbon Black, Inc. - installed 2019-01-16)
- [Running] com.carbonblack.daemon.plist (Carbon Black, Inc. - installed 2019-01-16)
- [Loaded] com.microsoft.OneDriveUpdaterDaemon.plist (Microsoft Corporation - installed 2019-01-09)
- [Loaded] com.microsoft.autoupdate.helper.plist (Microsoft Corporation - installed 2019-03-14)
- [Loaded] com.microsoft.office.licensingV2.helper.plist (Microsoft Corporation - installed 2017-07-02)
- [Not Loaded] com.paloaltonetworks.gp.pangpsd.plist (? fcd5eb13 - installed 2019-03-12)
- [Running] com.spsecure.daemon.plist (Veriato, Inc. - installed 2019-01-09)
- User Launch Agents:
- [Loaded] com.google.keystone.agent.plist (Google, Inc. - installed 2019-03-11)
- User Login Items:
- Enterprise Connect.app (Apple - installed 2019-01-09)
- (Application - /Applications/Enterprise Connect.app)
- OneDrive.app (Microsoft Corporation - installed 2019-03-12)
- ZoomOpener.app (Zoom Video Communications, Inc. - installed 2018-12-16)
- SharePointBrowserPlugin: 15.32 (Microsoft Corporation - installed 2017-03-09)
- MeetingJoinPlugin: 1.0 (? - installed 2019-01-09)
- User Internet Plug-ins:
- ZoomUsPlugIn: 4.1.35374.1217 (Zoom Video Communications, Inc. - installed 2019-01-17)
- CWSAssistantPlugin: 100 (? - installed 2018-12-11)
- Audio Plug-ins:
- AppleTimeSyncAudioClock: 1.0 (Apple - installed 2018-11-30)
- BluetoothAudioPlugIn: 6.0.10 (Apple - installed 2019-02-27)
- AppleAVBAudio: 710.1 (Apple - installed 2018-11-30)
- BridgeAudioSP: 5.2 (Apple - installed 2019-02-27)
- iSightAudio: 7.7.3 (Apple - installed 2018-11-30)
- Time Machine:
- System Load: 1.18 (1 min ago) 4.95 (5 min ago) 12.17 (15 min ago)
- File system: 28.31 seconds
- Read speed: 1685 MB/s
- CPU Usage Snapshot:
- System 3 %
- Idle 93 %
- Top Processes Snapshot by CPU:
- Other processes 18.63 % (?)
- OneDrive 1.67 % (Microsoft Corporation)
- Google Chrome 0.58 % (Google, Inc.)
- Top Processes Snapshot by Memory:
- EtreCheck 581 MB (App Store)
- Finder 220 MB (Apple)
- Console 157 MB (Apple)
- Top Processes Snapshot by Network Use:
- mDNSResponder 8 MB / 7 MB (Apple)
- CbOsxSensorService 16 KB / 269 KB (Carbon Black, Inc.)
- netbiosd 48 KB / 33 KB (Apple)
- Physical RAM: 16 GB
- Free RAM: 5.47 GB
- Cached files: 3.37 GB
- Available RAM: 8.84 GB
- Install Date Name (Version)
- 2019-03-12 Bit9 Platform (7.2.3.4000)
- 2019-03-13 LastPass (4.4.0)
- 2019-03-13 Slack (3.3.8)
- 2019-03-13 Microsoft OneNote (16.23.19030902)
- 2019-03-13 Microsoft PowerPoint (16.23.19030902)
- 2019-03-14 Microsoft AutoUpdate (4.9.19030902)
- 2019-03-21 VMware Workspace ONE Intelligent Hub (3.3.0.498)
- 2019-03-25 08:54:31 kcm Crash
- Executable: /System/Library/PrivateFrameworks/Heimdal.framework/Helpers/kcm
- dyld3 mode
- Executable: /System/Library/PrivateFrameworks/MobileAccessoryUpdater.framework/Support/fud
- objc_msgSend() selector name: setPluginInstance:withVersion:pluginName
- dyld3 mode
- Executable: /Applications/Microsoft Word.app
- Performing @selector(terminate:) from sender NSMenuItem 0x600000d30900
- 3rd party kernel extensions:
- com.bit9.KernelKauth
- com.bit9.SystemProxy.7.2.3f8
- com.carbonblack.CbOsxSensorNetmon
- com.paloaltonetworks.kext.pangpd
- End of report