Link following in Zoom Workplace Desktop App for Windows - CVE-2020-11443
Published: May 5, 2020
Zoom Workplace Desktop App for Windows
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to MSI installer in Zoom follows symbolic links. A local user can place a specially crafted file into a writable location, trick the victim into installing Zoom client into that location and execute arbitrary code on the system with elevated privileges.