Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6j86-v54w-73w8

Опубликовано: 13 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.

EPSS

Процентиль: 6%
0.00025
Низкий

8.7 High

CVSS3

Дефекты

CWE-269
CWE-347

Связанные уязвимости

CVSS3: 8.7
nvd
больше 2 лет назад

Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.

CVSS3: 8.7
fstec
больше 2 лет назад

Уязвимость программного обеспечения для проведения видеоконференций Zoom, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 6%
0.00025
Низкий

8.7 High

CVSS3

Дефекты

CWE-269
CWE-347