VYPR

Zoom Rooms for Conference Room for Windows

by Zoom Video Communications, Inc.

CVEs (17)

  • CVE-2022-36930HigJan 9, 2023
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.

  • CVE-2022-28763HigOct 31, 2022
    risk 0.57cvss 8.8epss 0.01

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading…

  • CVE-2022-28752HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

  • CVE-2023-36538HigJul 11, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-36536HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-34119HigJul 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-39212HigAug 8, 2023
    risk 0.51cvss 7.9epss 0.00

    Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

  • CVE-2022-36929HigJan 9, 2023
    risk 0.51cvss 7.8epss 0.00

    The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

  • CVE-2022-22782HigApr 28, 2022
    risk 0.51cvss 7.9epss 0.00

    The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was…

  • CVE-2021-34411HigSep 27, 2021
    risk 0.51cvss 7.8epss 0.00

    During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege…

  • CVE-2021-34409HigSep 27, 2021
    risk 0.51cvss 7.8epss 0.00

    It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy…

  • CVE-2022-22786HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.02

    The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a…

  • CVE-2023-36537HigJul 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2023-34118HigJul 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

  • CVE-2022-22788HigJun 15, 2022
    risk 0.46cvss 7.1epss 0.01

    The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for…

  • CVE-2023-22880MedMar 16, 2023
    risk 0.44cvss 6.8epss 0.01

    Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom…

  • CVE-2022-28764LowNov 14, 2022
    risk 0.21cvss 3.3epss 0.00

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure…