Privilege Escalation Vulnerability in Zoom Desktop Client for Windows
CVE-2023-36541

8HIGH

Key Information:

Vendor
CVE Published:
8 August 2023

Summary

The Zoom Desktop Client for Windows contains a vulnerability that arises from insufficient verification of data authenticity. This flaw enables an authenticated user to potentially escalate privileges through network access, allowing them to perform actions that they are normally restricted from executing. It is essential that users upgrade to the latest version 5.14.5 or higher to safeguard against this issue and ensure the integrity of their systems.

Affected Version(s)

Zoom Desktop Client for Windows Windows before 5.14.5

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.