Privilege Escalation Flaw in Zoom Desktop Client for Windows
CVE-2023-36540

7.3HIGH

Key Information:

Vendor
CVE Published:
8 August 2023

Summary

A vulnerability has been identified in the installer for the Zoom Desktop Client for Windows, permitting an authenticated user to exploit an untrusted search path. This may lead to an escalation of privileges, allowing the user to execute unauthorized actions within the system. Users of the affected versions are advised to update promptly to mitigate potential security risks.

Affected Version(s)

Zoom Desktop Client for Windows Windows before 5.14.5

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.