PT-2024-13775 · Zoom · Zoom Vdi Client For Windows+2

Sim0Nsecurity

·

Published

2024-01-10

·

Updated

2024-09-20

·

CVE-2023-49647

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Desktop Client for Windows versions prior to 5.16.10 Zoom VDI Client for Windows versions prior to 5.16.10 Zoom SDK for Windows versions prior to 5.16.10
Description The issue is related to improper access control in Zoom products for Windows, which may allow an authenticated user to conduct an escalation of privilege via local access.
Recommendations For Zoom Desktop Client for Windows versions prior to 5.16.10, update to version 5.16.10 or later. For Zoom VDI Client for Windows versions prior to 5.16.10, update to version 5.16.10 or later. For Zoom SDK for Windows versions prior to 5.16.10, update to version 5.16.10 or later.

Fix

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2023-49647

Affected Products

Zoom Desktop Client For Windows
Zoom Sdks For Windows
Zoom Vdi Client For Windows