CVE-2022-36925

MEDIUM

Zoom Rooms < 5.11.4 - Local Privilege Escalation via Hard-coded Cryptographic Key

Title source: llm
STIX 2.1

Description

Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service.

References (1)

Core 1

Scores

CVSS v3 4.4
EPSS 0.0012
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-321 CWE-798
Status published
Products (1)
zoom/rooms < 5.11.4
Published Jan 09, 2023
Tracked Since Feb 18, 2026