Local Privilege Escalation in Zoom Client for Meetings for macOS

  • ZSB-22017
  • CVE-2022-28751
  • High
  • 8.8
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The Zoom Client for Meetings for macOS (Standard and for IT Admin) before version 5.11.3 contain a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • Zoom Client for Meetings for macOS (Standard and for IT Admin) before version 5.11.3

Reported by Patrick Wardle of Objective-See

Revision Date Description
1.0 08/09/2022

Initial Publication