QID 379381
Date Published: 2024-02-21
QID 379381: Zoom Desktop Client, VDI Client and Zoom Rooms Client for Windows Untrusted Search Path Vulnerability (ZSB-24004)
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.
Zoom has released a security update for zoom to fix the vulnerabilities.
Affected Versions:
Zoom Desktop Client for Windows before version 5.17.0
Zoom VDI Client for Windows before version 5.17.5 (excluding 5.15.15 and 5.16.12)
Zoom Rooms Client for Windows before version 5.17.0
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable 32 bit Zoom products using registry entry for windows OS.
Successful exploitation of this vulnerability could lead to escalation of privilege via local access.
Solution
Customers are advised to upgrade to Zoom Client 5.17.0(Windows), 5.17.5(Windows), 5.17.0(Windows), 5.17.0(Windows) or later to remediate these vulnerabilities.
Vendor References
CVEs related to QID 379381
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-24004 |
|