ZeroHour
Security Affairspublished ()ingested @securityaffairs

Zoom Rooms was affected by four "high" severity vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-36930
+4 in the same advisory: …36926 …36929 …36927 …36925
Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability.

Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.

NVD description · AI analysis pending
7.8<1%
  • zoom rooms
CVE-2022-36928
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability.

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.

NVD description · AI analysis pending
7.1<1%
  • zoom zoom
Full article231 words · extracted from securityaffairs.com · click to collapse

Zoom addressed four “high” severity vulnerabilities impacting its popular videoconferencing software Zoom Rooms.

Zoom addressed four “high” severity vulnerabilities impacting its videoconferencing platform Zoom Rooms.

Below are the details for the bugs addressed by the company:

CVE-2022-36930 (CVSS Score 8.2) – Local Privilege Escalation in Rooms for Windows Installers.

The issue affects Rooms for Windows installers before version 5.13.0.

“A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.” reads the advisory published by the company.

CVE-2022-36929 – (CVSS Score 7.8) – Local Privilege Escalation in Rooms for Windows Clients.

The flaw affects Rooms for Windows clients before version 5.12.7. A local low-privileged user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

CVE-2022-36926 – CVE-2022-36927 – (CVSS Score 8.8) – Local Privilege Escalation in Zoom Rooms for macOS Clients. The flaw affects Rooms for macOS clients before version 5.11.3. The issue can be exploited by a local low-privileged user to escalate their privileges to root.

The communications technology company also addressed two “Medium” severity bugs:

  • CVE-2022-36928 – (CVSS Score 6.1) – Path Traversal in Zoom for Android Clients.
  • CVE-2022-36925 – (CVSS Score 4.4) – Insecure key generation for Zoom Rooms for macOS Clients

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Rooms)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/140607/security/zoom-rooms-vulnerabilities.html