External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.
The vulnerability classified as CWE-73 (External Control of File Name or Path) and CWE-610 allows an external attacker to influence the file name or path used by the Mail function of the application. No authentication or local account is required — the attack can be carried out remotely over the network. User interaction (UI:R) is required to trigger the vulnerability, meaning the victim must perform a certain action, such as opening a message or clicking an element in the interface. The vulnerability can lead to privilege escalation through file or path manipulation by the application.
An unauthorized attacker can escalate privileges on the victim's system, potentially gaining access to sensitive data, modifying it, or causing service unavailability (full impact on confidentiality, integrity, and availability).
Zoom Workplace for Windows should be updated to version 6.6.0 or newer. Detailed information is available in the vendor's security bulletin: https://www.zoom.com/en/trust/security-bulletin/zsb-26005
Zoom Workplace Desktop for Windows in versions prior to 6.6.0, Zoom Workplace Virtual Desktop Infrastructure (VDI) — versions indicated in vendor references.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HZoom Workplace Desktop
APPZoom< 6.6.0Zoom Workplace Virtual Desktop Infrastructure
APPZoom6.4.0 – 6.4.17 (excl.)6.5.0 – 6.5.15 (excl.)6.6.0 – 6.6.10 (excl.)
Related vulnerabilities
Przejęcie konta przez sieć — błąd walidacji w Zoom Client dla Windows
Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć
Privilege escalation przez TOCTOU w Zoom Client dla Windows
TOCTOU race condition w Zoom Client dla Windows — privilege escalation
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before vers...