Zoom Clients for Windows Improper Privilege Management Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability exists in certain Zoom Clients for Windows, prior to version 6.6.0, that improperly manages privileges. This flaw may enable an authenticated user to escalate privileges through local access. Affected products include Zoom Workplace for Windows, Zoom Workplace VDI Client for Windows (versions prior to 6.4.15, 6.5.13, and 6.6.10 in their respective branches), and Zoom Rooms for Windows (versions prior to 6.6.0).
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access within the application or system.
Remediation
Users are advised to update to the latest version of Zoom Clients for Windows. The latest version can be downloaded from the Zoom Download Center.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
