Improper Authentication in Zoom Clients Before Version 5.16.5
CVE-2023-49646

6.5MEDIUM

What is CVE-2023-49646?

An improper authentication flaw exists in specific Zoom clients prior to version 5.16.5. This vulnerability could potentially enable an authenticated user to exploit the system by orchestrating a denial of service through network access, potentially causing disruptions in service availability. Users are urged to update their Zoom clients to the latest version to mitigate this risk effectively.

Affected Version(s)

Zoom Clients Windows See references

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.