Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Meeting_software_development_kit | Zoom | * | 6.4.0 (excluding) |
| Rooms | Zoom | * | 6.4.0 (excluding) |
| Rooms_controller | Zoom | * | 6.4.0 (excluding) |
| Workplace | Zoom | * | 6.4.0 (excluding) |
| Workplace_desktop | Zoom | * | 6.4.0 (excluding) |
| Workplace_virtual_desktop_infrastructure | Zoom | * | 6.1.17 (excluding) |
| Workplace_virtual_desktop_infrastructure | Zoom | 6.1.18 (including) | 6.2.13 (excluding) |
| Workplace_virtual_desktop_infrastructure | Zoom | 6.2.14 (including) | 6.3.10 (excluding) |