Impact
A time‑of‑check to time‑of‑use race condition exists in the installation and uninstallation processes of Zoom Clients for Windows. An authenticated local user can trigger the condition and potentially gain higher privileges on the infected host.
Affected Systems
Zoom Communications Zoom Clients running on Windows are potentially affected. The issue is tied to the generic installation and uninstallation paths used by the client, and no specific version numbers are provided, so all deployed Windows Zoom clients should be considered vulnerable until patched.
Risk and Exploitability
The CVSS score of 7 indicates high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an authenticated user must initiate a concurrent install or uninstall operation. While exploitation would remain limited to the authenticated user’s privileges, the potential for privilege escalation warrants prompt remediation.
OpenCVE Enrichment