Local Privilege Escalation in Auto Updater for Zoom Client for Meetings for macOS

  • ZSB-22019
  • CVE-2022-28757
  • High
  • 8.8
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

Note: This issue allows for a bypass of the patch issued in 5.11.5 to address CVE-2022-28756.

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • Zoom Client for Meetings for macOS (Standard and for IT Admin) starting version 5.7.3 and before version 5.11.6

Reported by Csaba Fitzl (theevilbit) of Offensive Security

Revision Date Description
1.0 08/17/2022

Initial Publication