Impact
The vulnerability exists in Zoom Rooms for Windows prior to version 7.1.0 and is caused by improper privilege management. An authenticated local user can exploit this flaw to elevate their privileges on the host system. This allows the attacker to gain higher‑level access than intended, enabling potential execution of arbitrary code with elevated authority. The weakness is categorized as CWE‑20, reflecting inadequate input or state validation during privilege handling.
Affected Systems
Zoom Communications’ Zoom Rooms application running on Windows machines with versions earlier than 7.1.0 are impacted. Users who can log into Zoom Rooms with credentials that provide local access are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity condition for privilege escalation. The EPSS score of less than 1% shows that, at this time, the exploitation probability in the wild is low. The flaw is not listed in the CISA KEV catalog, and the attack vector is local, requiring authenticated access to Zoom Rooms on the targeted machine. Inherited from the data, the vulnerability would likely be leveraged by insiders or attackers who have compromised a user credential and then attempt to elevate rights on the same host.
OpenCVE Enrichment