The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
https://securityaffairs.com/170861/security/zoom-fixed-two-high-severity-flaws.html