Zoom Workplace
- < 7.0.5
A race condition vulnerability has been identified in the installation and uninstallation processes of certain Zoom Clients for Windows. This time-of-check to time-of-use (TOCTOU) race condition could allow an authenticated local user to escalate privileges. The vulnerability affects Zoom Workplace for Windows versions prior to 7.0.5, Zoom Workplace VDI Client for Windows versions prior to 6.5.17 and 6.6.14 in their respective branches, the Zoom Workplace VDI plugin for Windows in the same version ranges, Zoom Rooms for Windows prior to 7.0.5, and Remote Control for Zoom Contact Center for Windows before version 7.0.0.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access within the Zoom application or system.
Users are advised to update to the latest version of Zoom Clients for Windows. The latest version can be downloaded from the Zoom Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.