The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.