PT-2023-5591 · Zoom · Zoom Client Sdk

Published

2023-08-08

·

Updated

2024-09-27

·

CVE-2023-39214

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Zoom Client SDK versions prior to 5.15.5
Description The issue is related to insufficient protection of service data, which may allow a remote attacker to gain unauthorized access to protected information. It involves exposure of sensitive information in Zoom Client SDK, potentially enabling an authenticated user to cause a denial of service via network access.
Recommendations For Zoom Client SDK versions prior to 5.15.5, update to version 5.15.5 or later to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Fix

Exposure of Resource to Wrong Sphere

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06245
CVE-2023-39214

Affected Products

Zoom Client Sdk