The vulnerability exists due to usage of an untrusted search path. A local user can place a malicious binary into a specific location on the system and execute arbitrary code with escalated privileges.
https://securityaffairs.com/170861/security/zoom-fixed-two-high-severity-flaws.html