Learn about CVE-2020-11443 affecting Zoom IT installer for Windows. Find out how standard users can delete files in %APPDATA%\Zoom, leading to unauthorized deletions. Take immediate steps to update and secure your system.
Zoom IT installer for Windows prior to version 4.6.10 has a vulnerability that allows standard users to delete files in %APPDATA%\Zoom, potentially leading to unauthorized file deletions.
Understanding CVE-2020-11443
This CVE describes a privilege escalation vulnerability in the Zoom IT installer for Windows.
What is CVE-2020-11443?
The Zoom IT installer for Windows (ZoomInstallerFull.msi) before version 4.6.10 allows standard users to delete files in %APPDATA%\Zoom, potentially leading to unauthorized file deletions.
The Impact of CVE-2020-11443
The vulnerability allows users to manipulate the installer to delete files that they would not typically have permission to delete, potentially causing data loss or system instability.
Technical Details of CVE-2020-11443
This section provides detailed technical information about the CVE.
Vulnerability Description
The Zoom IT installer for Windows prior to version 4.6.10 allows standard users to delete files in %APPDATA%\Zoom, exploiting SYSTEM privileges.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your system from CVE-2020-11443 with these mitigation strategies.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates