CVE-2020-9767

HIGH

Zoom Sharing Service - Uncontrolled Search Path Element via DLL Loading

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-9767. PoCs published by shubham0d.

AI-analyzed exploit summary This repository contains a functional DLL hijacking exploit for Zoom versions prior to 5.1.3, leveraging the absence of `SHCore.dll` on older Windows systems. The exploit involves placing a malicious `SHCore.dll` in Zoom's application directory, which gets loaded and executed when Zoom starts or performs certain actions.

Description

A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine on which the service was running with elevated privileges to elevate their system privileges as well through use of a malicious DLL. Zoom addressed this issue, which only applies to Windows users, in the 5.0.4 client release.

Exploits (1)

nomisec WORKING POC 1 stars
by shubham0d · poc
https://github.com/shubham0d/Zoom-dll-hijacking

This repository contains a functional DLL hijacking exploit for Zoom versions prior to 5.1.3, leveraging the absence of `SHCore.dll` on older Windows systems. The exploit involves placing a malicious `SHCore.dll` in Zoom's application directory, which gets loaded and executed when Zoom starts or performs certain actions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zoom Meeting < 5.1.3
No auth needed
Prerequisites: Target system must be running Windows 7 or earlier, Windows Server 2008, or any Windows system without `SHCore.dll` · Attacker must have write access to `C:\Users\$user\AppData\Roaming\Zoom\bin\`
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0080
EPSS Percentile 51.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
zoom/sharing_service 5.0.4
Published Aug 14, 2020
Tracked Since Feb 18, 2026