CVE-2022-28768CWE-689

Local Privilege Escalation in Zoom Client Installer for macOS

High · published November 17, 2022

CVSS v3.1
8.8
EPSS
0%
Percentile
8.4
In the wild
Unconfirmed
What it is

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00187 · 8.4th percentile
Weakness
CWE-689 · Permission Race Condition During Resource Copy
Published
2022-11-17T22:36Z
EPSS history
Timeline
  • 17 NOV 22:36Z
    Local Privilege Escalation in Zoom Client Installer for macOS
    cvelistv5