First published: Fri Aug 14 2020(Updated: )
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9767 is considered a high severity vulnerability due to the potential for privilege escalation.
To fix CVE-2020-9767, update the Zoom Sharing Service to version 5.0.5 or later.
CVE-2020-9767 allows attackers to exploit DLL hijacking to elevate their privileges on the system.
CVE-2020-9767 affects users of Zoom Sharing Service version 5.0.4 on Windows.
Exploitation of CVE-2020-9767 could lead to unauthorized access to system resources and data.