Privilege Escalation Vulnerability in Zoom Desktop Client for Windows
CVE-2023-39216

9.6CRITICAL

Key Information:

Vendor
CVE Published:
8 August 2023

Summary

An improper input validation flaw in the Zoom Desktop Client for Windows versions prior to 5.14.7 poses a risk by potentially allowing an unauthenticated user to exploit network access for privilege escalation. This vulnerability emphasizes the importance of securing user input to prevent unauthorized privilege gains.

Affected Version(s)

Zoom Desktop Client for Windows Windows before 5.14.7

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.