PT-2022-5815 · Zoom · Zoom Client For Meetings Installer For Macos
Published
2022-11-15
·
Updated
2022-11-22
·
CVE-2022-28768
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoom Client for Meetings Installer for macOS versions prior to 5.12.6
Description
The issue is related to a local privilege escalation vulnerability. A local low-privileged user could exploit this during the install process to escalate their privileges to root. The vulnerability is caused by a race condition during the copying of resources, which may allow an attacker to elevate their privileges.
Recommendations
For versions prior to 5.12.6, update to version 5.12.6 or later to resolve the issue. As a temporary workaround, consider restricting the installation of the Zoom Client for Meetings Installer for macOS to authorized personnel only, until a patch is applied.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoom Client For Meetings Installer For Macos