Executive brief
A security vulnerability exists in the installer for Zoom Rooms for Windows, a software solution used to manage conference room hardware and meetings. An attacker with existing low-level access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the system, potentially leading to unauthorized data access or persistent control over the conference room environment.
Technical details
An untrusted search path vulnerability (CWE-426) exists in the installer for Zoom Rooms for Windows prior to version 7.0.0. The flaw occurs because the installer may attempt to load resources or libraries from an insecure directory that can be modified by a standard user. A local, authenticated attacker can exploit this by placing a malicious file in the search path, which the installer then executes with elevated permissions. Successful exploitation allows a low-privileged user to gain full administrative rights on the affected Windows system. The issue is resolved in Zoom Rooms for Windows version 7.0.0.
Affected products
- Zoom Rooms before version 7.0.0
Timeline
- 2026-05-12: advisory: Initial publication by Zoom (ZSB-26008)
- 2026-05-13: disclosed: NVD publication date