Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HZoom Rooms
APPZoom< 7.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-49457CRITICAL9.6PL ✓same product
Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć
CVE-2024-24691CRITICAL9.6PL ✓same product
Privilege escalation w Zoom Desktop Client, VDI Client i Meeting SDK dla Windows
CVE-2026-53410HIGH7.0PL ✓same product
TOCTOU race condition w Zoom Client dla Windows — privilege escalation
CVE-2026-53409HIGH7.8PL ✓same product
Privilege escalation w Zoom Rooms dla Windows (przed wersją 7.1.0)
CVE-2026-30902HIGH7.8same product
Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct a...