CVE-2022-36930

Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*

History

21 Nov 2024, 07:14

Type Values Removed Values Added
References () https://explore.zoom.us/en/trust/security/security-bulletin/ - Vendor Advisory () https://explore.zoom.us/en/trust/security/security-bulletin/ - Vendor Advisory
Summary
  • (es) Los instaladores de Zoom Rooms para Windows anteriores a la versión 5.13.0 contienen una vulnerabilidad de escalada de privilegios local. Un usuario local con pocos privilegios podría aprovechar esta vulnerabilidad en una cadena de ataque para escalar sus privilegios al usuario SYSTEM.
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 8.8

Information

Published : 2023-01-09 19:15

Updated : 2024-11-21 07:14


NVD link : CVE-2022-36930

Mitre link : CVE-2022-36930

CVE.ORG link : CVE-2022-36930


JSON object : View

Products Affected

zoom

  • rooms
CWE
CWE-427

Uncontrolled Search Path Element

NVD-CWE-noinfo