PT-2023-2184 · Zoom+1 · Zoom+3
Published
2023-01-09
·
Updated
2023-03-27
·
CVE-2023-22880
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoom for Windows clients versions 5.13.2 and earlier
Zoom Rooms for Windows clients versions 5.13.4 and earlier
Zoom VDI for Windows clients versions 5.13.0 and earlier
Description
The issue is related to an information disclosure vulnerability due to insufficient protection of service data when transmitting text online instead of using the local service. This vulnerability may allow a remote attacker to gain unauthorized access to protected information. The vulnerability is caused by a recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, which transmitted text to Microsoft's online Spellcheck service instead of the local Windows Spellcheck.
Recommendations
For Zoom for Windows clients versions 5.13.2 and earlier, update Zoom to version 5.13.3 or later to remediate the vulnerability by disabling the feature.
For Zoom Rooms for Windows clients versions 5.13.4 and earlier, update Zoom to version 5.13.5 or later to remediate the vulnerability by disabling the feature.
For Zoom VDI for Windows clients versions 5.13.0 and earlier, update Zoom to version 5.13.1 or later to remediate the vulnerability by disabling the feature.
As an alternative, update Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restart Zoom to remediate the vulnerability by updating Microsoft's telemetry behavior.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edge Webview2
Zoom
Zoom Rooms
Zoom Vdi