PT-2023-1335 · Zoom · Zoom Rooms For Macos

Published

2023-01-09

·

Updated

2023-01-13

·

CVE-2022-36926

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Rooms for macOS versions prior to 5.11.3
Description The issue exists due to the failure to neutralize special elements used in the operating system command. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.
Recommendations For versions prior to 5.11.3, update to version 5.11.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive system resources to minimize the risk of exploitation.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-00636
CVE-2022-36926

Affected Products

Zoom Rooms For Macos