CVE-2022-36929

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*

History

21 Nov 2024, 07:14

Type Values Removed Values Added
References () https://explore.zoom.us/en/trust/security/security-bulletin/ - Vendor Advisory () https://explore.zoom.us/en/trust/security/security-bulletin/ - Vendor Advisory
Summary
  • (es) El instalador de Zoom Rooms para Windows anterior a 5.12.6 contiene una vulnerabilidad de escalada de privilegios local. Un usuario local con pocos privilegios podría aprovechar esta vulnerabilidad durante el proceso de instalación para escalar sus privilegios al usuario SYSTEM.

Information

Published : 2023-01-09 19:15

Updated : 2024-11-21 07:14


NVD link : CVE-2022-36929

Mitre link : CVE-2022-36929

CVE.ORG link : CVE-2022-36929


JSON object : View

Products Affected

zoom

  • rooms
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

NVD-CWE-noinfo