Memory Buffer Integrity Issues in Zoom for Windows Clients
CVE-2023-28601
6.5MEDIUM
Key Information:
- Status
- Vendor
- CVE Published:
- 13 June 2023
What is CVE-2023-28601?
A vulnerability in Zoom for Windows clients prior to version 5.14.0 allows potential unauthorized alteration of the Zoom Client's memory buffer. This flaw could lead to integrity issues within the application if exploited by a malicious actor. The improper restriction of operations may enable attackers to manipulate the protected memory space, posing risks to user data and overall application performance.
Affected Version(s)
Zoom for Windows Client before 5.14.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved