Vulnerability Description
A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Sharing Service | 5.0.4 |
Related Weaknesses (CWE)
References
- https://support.zoom.us/hc/en-us/articles/360044350792-Security-CVE-2020-9767Broken LinkVendor Advisory
- https://support.zoom.us/hc/en-us/articles/360044350792-Security-CVE-2020-9767Broken LinkVendor Advisory
FAQ
What is CVE-2020-9767?
CVE-2020-9767 is a vulnerability with a CVSS score of 7.8 (HIGH). A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated pri...
How severe is CVE-2020-9767?
CVE-2020-9767 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9767?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Sharing Service.