First published: Thu Nov 17 2022(Updated: )
The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Rooms | <5.12.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36924 is a local privilege escalation vulnerability in the Zoom Rooms Installer for Windows prior to version 5.12.6.
CVE-2022-36924 allows a local low-privileged user to escalate their privileges to the SYSTEM user during the installation process of Zoom Rooms for Windows.
CVE-2022-36924 has a severity rating of high (7.8).
To fix CVE-2022-36924, users should update their Zoom Rooms Installer for Windows to version 5.12.6 or later.
More information about CVE-2022-36924 can be found on the Zoom Security Bulletin at https://explore.zoom.us/en/trust/security/security-bulletin/