Link following in Zoom Workplace Desktop App for Windows - CVE-2020-11443

 

Link following in Zoom Workplace Desktop App for Windows - CVE-2020-11443

Published: May 5, 2020


Vulnerability identifier: #VU27546
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11443
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to MSI installer in Zoom follows symbolic links. A local user can place a specially crafted file into a writable location, trick the victim into installing Zoom client into that location and execute arbitrary code on the system with elevated privileges.


Affected software

Zoom Workplace Desktop App for Windows

How to mitigate CVE-2020-11443

Install updates from vendor's website.

Zoom Workplace Desktop App for Windows - update to 4.6.10 20033.0407

External References

Related Security Bulletins