Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
Any version before 7.0.4
affected
Description
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
Problem types
CWE-939 Improper authorization in handler for custom URL scheme
Product status
Any version before 7.0.4
References
www.zoom.com/en/trust/security-bulletin/zsb-26010