QID 376624

Date Published: 2022-05-23

QID 376624: Zoom Client Local privilege escalation Vulnerability (ZSB-22004)

Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.

Affected Versions:
Zoom Client for Meetings for Windows prior to version 5.9.7

QID Detection Logic:
This authenticated QID detects vulnerable Zoom Client for Windows prior to version 5.9.7

Successful exploit may cause integrity, availability and susceptible to a local privilege escalation issues

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as High - 6.6 severity.
  • Solution
    Customers are advised to upgrade to Zoom Client or later to remediate these vulnerabilities.

    Vendor References

    CVEs related to QID 376624

    Software Advisories
    Advisory ID Software Component Link
    ZSB-22004 URL Logo explore.zoom.us/en/trust/security/security-bulletin/