PT-2024-13775 · Zoom · Zoom Vdi Client For Windows+2
Sim0Nsecurity
·
Published
2024-01-10
·
Updated
2024-09-20
·
CVE-2023-49647
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoom Desktop Client for Windows versions prior to 5.16.10
Zoom VDI Client for Windows versions prior to 5.16.10
Zoom SDK for Windows versions prior to 5.16.10
Description
The issue is related to improper access control in Zoom products for Windows, which may allow an authenticated user to conduct an escalation of privilege via local access.
Recommendations
For Zoom Desktop Client for Windows versions prior to 5.16.10, update to version 5.16.10 or later.
For Zoom VDI Client for Windows versions prior to 5.16.10, update to version 5.16.10 or later.
For Zoom SDK for Windows versions prior to 5.16.10, update to version 5.16.10 or later.
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoom Desktop Client For Windows
Zoom Sdks For Windows
Zoom Vdi Client For Windows