Impact
Improper input validation in the Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK for Windows allows an unauthenticated attacker to exploit the client over the network and gain control of a Zoom account. Because the flaw does not require prior authentication, any network user who can reach the client can craft malicious input that is processed as a valid authentication request, resulting in an account takeover.
Affected Systems
The affected product is Zoom Communications’ Zoom Workplace for Windows, encompassing the Desktop Client, the VDI Client, and the Zoom Meeting SDK for Windows. Specific affected versions are not disclosed in the advisory, so all installations of these components should be treated as potentially vulnerable until a patch is installed.
Risk and Exploitability
The CVSS score of 9.8 reflects a high risk for loss of account integrity. The EPSS of less than 1% signals that exploitation is presently unlikely, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need only network access to the Zoom client to send malformed data that triggers the flaw and hijack the account. Once successful, the attacker would possess full authority over the victim’s Zoom account.
OpenCVE Enrichment