Path traversal in Zoom Workplace Desktop App for Windows - CVE-2020-6109
Published: June 4, 2020
Zoom Workplace Desktop App for Windows
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated attacker can send a specially crafted chat message and cause an arbitrary file write, leading to arbitrary code execution.