Local Privilege Escalation in Zoom Client Installer for macOS

  • ZSB-22029
  • CVE-2022-28768
  • High
  • 8.8
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6

Reported by Koh M. Nakagawa (tsunekoh)

Revision Date Description
1.0 11/15/2022

Initial Publication