Vulnerability identifier: #VU109003
Vulnerability risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-78
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Zoom Workplace Desktop App for Windows
Client/Desktop applications /
Office applications
Zoom Workplace Desktop App for macOS
Client/Desktop applications /
Office applications
Zoom Workplace Desktop App for Linux
Client/Desktop applications /
Office applications
Zoom Rooms Controller for Windows
Client/Desktop applications /
Office applications
Zoom Rooms Controller for macOS
Client/Desktop applications /
Office applications
Zoom Rooms Controller for Linux
Client/Desktop applications /
Office applications
Zoom Rooms Client for Windows
Client/Desktop applications /
Office applications
Zoom Rooms Client for macOS
Client/Desktop applications /
Office applications
Zoom Workplace App for iOS
Mobile applications /
Apps for mobile phones
Zoom Workplace App for Android
Mobile applications /
Apps for mobile phones
Zoom Rooms Controller for Android
Mobile applications /
Apps for mobile phones
Zoom Rooms Client for Android
Mobile applications /
Apps for mobile phones
Zoom Rooms Client for iPad
Mobile applications /
Apps for mobile phones
Zoom Meeting SDK for Windows
Universal components / Libraries /
Software for developers
Zoom Meeting SDK for iOS
Universal components / Libraries /
Software for developers
Zoom Meeting SDK for Android
Universal components / Libraries /
Software for developers
Zoom Meeting SDK for macOS
Universal components / Libraries /
Software for developers
Zoom Meeting SDK for Linux
Universal components / Libraries /
Software for developers
Virtual Desktop Infrastructure (VDI)
Server applications /
Conferencing, Collaboration and VoIP solutions
Vendor: Zoom Video Communications, Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation. A local user can execute arbitrary OS commands on the target system with elevated privileges.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Zoom Workplace Desktop App for Windows: 0.9.10042.0911 - 6.4.0 62047
Zoom Workplace Desktop App for macOS: 4.6.9 19273.0402 - 6.3.11 50104
Zoom Workplace Desktop App for Linux: 5.1.418436.0628 - 6.3.11 7212
Zoom Workplace App for iOS: 4.6.10 20012.0407 - 6.3.11 22661
Zoom Workplace App for Android: 4.6.11 20553.0413 - 6.3.11 28196
Zoom Rooms Controller for Windows: 6.1.0 - 6.3.5
Zoom Rooms Controller for macOS: 6.1.0 - 6.3.5
Zoom Rooms Controller for Linux: 6.0.0 - 6.3.5
Zoom Rooms Controller for Android: 6.1.0 - 6.3.0
Zoom Rooms Client for Windows: 4.6.5 18374.0407 - 6.3.0
Zoom Rooms Client for macOS: 4.6.5 2040.0406 - 6.3.0
Zoom Rooms Client for Android: 5.15.10 - 6.3.0
Zoom Rooms Client for iPad: 5.15.10 - 6.3.0
Zoom Meeting SDK for Windows: 5.9.0 - 6.3.11
Zoom Meeting SDK for iOS: 5.9.0 - 6.3.10
Zoom Meeting SDK for Android: 5.9.0 - 6.3.10
Zoom Meeting SDK for macOS: 5.9.0 - 6.3.11
Zoom Meeting SDK for Linux: 5.15.5 - 6.3.10
Virtual Desktop Infrastructure (VDI): before
External links
https://www.zoom.com/en/trust/security-bulletin/ZSB-25017/
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.