CVE-2020-9767: High severity zoom vulnerability
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9767?
CVE-2020-9767 is considered a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2020-9767?
To fix CVE-2020-9767, update the Zoom Sharing Service to version 5.0.5 or later.
What is the exploit mechanism for CVE-2020-9767?
CVE-2020-9767 allows attackers to exploit DLL hijacking to elevate their privileges on the system.
Who is affected by CVE-2020-9767?
CVE-2020-9767 affects users of Zoom Sharing Service version 5.0.4 on Windows.
What are the potential consequences of CVE-2020-9767 exploitation?
Exploitation of CVE-2020-9767 could lead to unauthorized access to system resources and data.