PT-2023-1099 · Zoom · Zoom Rooms For Windows

CVE-2022-36930

·

Publicado

2023-01-06

·

Atualizado

2023-01-13

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Rooms for Windows versions prior to 5.13.0
Description The issue is related to an uncontrolled search path element in the Zoom video conferencing software. Exploitation of this issue could allow an attacker to elevate their privileges to the SYSTEM user. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.
Recommendations For Zoom Rooms for Windows versions prior to 5.13.0, update to version 5.13.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Zoom Rooms for Windows installer to minimize the risk of exploitation.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-00249
CVE-2022-36930

Produtos afetados

Zoom Rooms For Windows