Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://explore.zoom.us/en/trust/security/security-bulletin/ | vendor advisory |