PT-2023-5196 · Zoom · Zoom Desktop Client For Windows

Published

2023-07-11

·

Updated

2024-09-19

·

CVE-2023-34116

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoom Desktop Client for Windows versions prior to 5.15.0
Description The issue is related to improper input validation, which may allow an unauthorized user to enable an escalation of privilege via network access. This could potentially be exploited by a remote attacker to gain elevated privileges.
Recommendations For versions prior to 5.15.0, update to version 5.15.0 or later to resolve the issue. As a temporary workaround, consider restricting network access to the Zoom Desktop Client for Windows until the update can be applied.

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-05800
CVE-2023-34116

Affected Products

Zoom Desktop Client For Windows