Zoom Clients for Windows Privilege Escalation Vulnerability
Vulnerability
A vulnerability exists in certain Zoom Clients for Windows, specifically in the Zoom Workplace application, the VDI Client, and the Meeting SDK, all prior to version 6.6.11 in the 6.6.x branch, as well as the Zoom Workplace VDI Client for Windows version 6.6.10. This vulnerability arises from an improper check of the minimum version in the update functionality, which may allow an authenticated user to escalate privileges through local access.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation.
Remediation
Users are advised to update to the latest version of Zoom Clients for Windows. The updated version can be downloaded from the Zoom Download Center.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
