PT-2023-6937 · Zoom · Zoom Rooms For Macos

Published

2023-11-14

·

Updated

2023-11-21

·

CVE-2023-43590

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Rooms for macOS versions prior to 5.16.0
Description The issue is related to incorrect handling of symbolic links before accessing a file, which may allow an attacker to escalate their privileges. This can be exploited by an authenticated user via local access.
Recommendations For Zoom Rooms for macOS versions prior to 5.16.0, update to version 5.16.0 or later to resolve the issue. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.

Fix

Link Following

Weakness Enumeration

Related Identifiers

BDU:2023-07956
CVE-2023-43590

Affected Products

Zoom Rooms For Macos