Information Disclosure Vulnerability in Zoom Client SDK for Windows
CVE-2023-39210

5.5MEDIUM

Key Information:

Vendor
CVE Published:
8 August 2023

Summary

The Zoom Client SDK for Windows prior to version 5.15.0 has a vulnerability that allows authenticated users to access sensitive information stored in cleartext. This security flaw may enable information disclosure via local access, posing a risk to users who rely on the SDK for secure communication. It is crucial for users to update to the latest version to mitigate this security issue and protect sensitive data from unauthorized access.

Affected Version(s)

Zoom Client SDK for Windows Windows before 5.15.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.