Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
The vulnerability consists of improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. An attacker can send specially crafted data over the network to the vulnerable application without needing any authentication. User interaction is required (UI:R), meaning the victim must perform a specific action, such as opening a malicious link or joining a crafted meeting. This results in privilege escalation in the context of the attacked system.
An unauthenticated attacker can obtain elevated privileges on the victim's system, potentially leading to system takeover, breach of data confidentiality and integrity, and disruption of service availability.
Apply patches available from the vendor according to references — detailed information about patched versions is available in Zoom's security bulletin: https://www.zoom.com/en/trust/security-bulletin/ZSB-24008/
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, Zoom Meeting SDK for Windows, Zoom Rooms — versions indicated in vendor references (bulletin ZSB-24008)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HZoom Meeting Software Development Kit
APPZoom< 5.16.5Zoom Rooms
APPZoom< 5.17.0Zoom Vdi Windows Meeting Clients
APPZoom< 5.14.14< 5.15.12< 5.16.10Zoom
APPZoom< 5.16.5
Related vulnerabilities
Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć
Zoom Desktop Client i VDI Client — privilege escalation przez sieć
Nieprawidłowa walidacja danych wejściowych w Zoom Desktop Client dla Windows — privilege escalation
Path traversal w Zoom Desktop Client dla Windows — eskalacja uprawnień
Zoom Client — podatność parsowania URL umożliwiająca RCE