PT-2023-1099 · Zoom · Zoom Rooms For Windows
CVE-2022-36930
·
Publicado
2023-01-06
·
Atualizado
2023-01-13
CVSS v3.1
8.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoom Rooms for Windows versions prior to 5.13.0
Description
The issue is related to an uncontrolled search path element in the Zoom video conferencing software. Exploitation of this issue could allow an attacker to elevate their privileges to the SYSTEM user. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.
Recommendations
For Zoom Rooms for Windows versions prior to 5.13.0, update to version 5.13.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Zoom Rooms for Windows installer to minimize the risk of exploitation.
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoom Rooms For Windows