#VU79125 Untrusted search path in Zoom Workplace Desktop App for Windows - CVE-2023-36540
Published: August 8, 2023
Zoom Workplace Desktop App for Windows
Zoom Video Communications, Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path in the installer for Zoom Desktop Client for Windows. A local user can place a malicious file into the folder along with the installer application and execute arbitrary code with elevated privileges.