QID 375487
Date Published: 2021-04-27
QID 375487: Zoom Arbitrary File Deletion Vulnerability
Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
A vulnerability in how the Zoom Windows installer could allow a local Windows user to delete files.
Affected Versions:
Zoom version prior to 4.6.10
QID Detection Logic:
This authenticated QID detects zoom.exe versions by fetching a list of binaries from AppData\Roaming\Zoom\bin and from HKLM\SOFTWARE\Zoom\MSI
Successful exploitation of this vulnerability may allow an attacker to delete files on target system.
Solution
Customers are advised to refer Zoom security update
for more information
Vendor References
CVEs related to QID 375487
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoom Version 4.4.53932.0709 |
|