#VU28566 Path traversal in Zoom Workplace Desktop App for Windows - CVE-2020-6109
Published: June 4, 2020
Zoom Workplace Desktop App for Windows
Zoom Video Communications, Inc.
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated attacker can send a specially crafted chat message and cause an arbitrary file write, leading to arbitrary code execution.