Impact
A time‑of‑check to time‑of‑use race condition in the installation and uninstallation process of the Zoom Workplace VDI Plugin for Windows allows an authenticated local user to elevate privileges and potentially gain system‑level access. The flaw arises from improper input validation, classified as CWE‑20, and could compromise confidentiality, integrity, and availability by granting escalation of rights within the host system.
Affected Systems
The affected product is Zoom Communications' Zoom Workplace VDI Plugin for Windows. Specific version information is not provided, but the vulnerability applies to the installation and uninstallation process of the Zoom Workplace VDI Plugin on Windows operating systems. No further version data is available.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low current chance of exploitation. The flaw requires a local authenticated user to execute the exploit, making it not remotely exploitable but still significant for any user who has installer privileges. Although not listed in the CISA KEV catalog, the privilege escalation potential warrants timely patching.
OpenCVE Enrichment