Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv75-x87g-889h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

EPSS

Процентиль: 31%
0.00118
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость клиента для проведения аудио- и видеоконференций в режиме реального времени Zoom Client for Meetings for Windows, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 31%
0.00118
Низкий

Дефекты

CWE-269