VYPR
Unrated severityNVD Advisory· Published Nov 17, 2022· Updated Apr 29, 2025

Local Privilege Escalation in Zoom Client Installer for macOS

CVE-2022-28768

Description

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A low-privileged user on macOS can escalate to root during the Zoom Client for Meetings Installer process prior to version 5.12.6.

Vulnerability

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A low-privileged user on the system can exploit this vulnerability during the installation process to gain root privileges. The exact code path is triggered while the installer runs with elevated privileges, allowing the attacker to manipulate the installation sequence [1].

Exploitation

An attacker must already have local low-privileged access to the macOS system. No network position or additional authentication is required beyond the initial low-privileged user context. The exploit occurs during the Zoom installer execution; the attacker can intervene in the installation process (for example, through a race condition or improper permission handling) to escalate privileges. The symmetry of the environment may require accurate timing to hijack the installer’s privileged operations [1].

Impact

On successful exploitation, the attacker gains root-level access on the macOS system. This allows full control over the operating system, including reading and writing arbitrary files, installing kernel extensions, and bypassing security restrictions. The impact affects confidentiality, integrity, and availability of the entire system from the low-privilege starting point [1].

Mitigation

Zoom released version 5.12.6 of the Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) that fixes this vulnerability. Users should update to 5.12.6 or later. There is no public workaround other than upgrading, and the vulnerability is not known to be listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.