Path traversal in Zoom Workplace Desktop App for Windows - CVE-2020-6110

 

Path traversal in Zoom Workplace Desktop App for Windows - CVE-2020-6110

Published: June 4, 2020


Vulnerability identifier: #VU28567
CSH Severity: Medium
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-6110
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated attacker can send a specially crafted chat message and cause an arbitrary binary planting which could be abused to achieve arbitrary code execution


Affected software

Zoom Workplace Desktop App for Windows

How to mitigate CVE-2020-6110

Install update from vendor's website.

Zoom Workplace Desktop App for Windows - update to 4.6.12 20613.0421

External References

Related Security Bulletins