this isn't the first time zoom got caught red-handed[1]. Last year they were called out for installing a local web server in order to disable security controls to get around the deprecated NPAPI[2] ... this is literally what malware does.
About the same time this story broke I interviewed for a Paris based AppSec company and their CTO asked me to install Zoom. It was really awkward because I had to ask: "Is this a trick question??"
Seriously I wouldn't touch Zoom with a 20 foot stick!
[1] https://medium.com/bugbountywriteup/zoom-zero-day-4-million-...