CVE-2022-28768

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
17/11/2022
Last modified:
22/11/2022

Description

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:* 5.12.6 (excluding)


References to Advisories, Solutions, and Tools