Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34120


Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.


Published

2023-06-13T18:15:21.913

Last Modified

2024-11-21T08:06:35.410

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.7 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-347
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zoom virtual_desktop_infrastructure < 5.14.0 Yes
Operating System microsoft windows - No

References