Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-43586


Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.


Published

2023-12-13T23:15:07.660

Last Modified

2024-11-21T08:24:26.853

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-426
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zoom meeting_software_development_kit < 5.16.5 Yes
Application zoom video_software_development_kit < 5.16.5 Yes
Application zoom virtual_desktop_infrastructure < 5.14.14 Yes
Application zoom virtual_desktop_infrastructure < 5.15.12 Yes
Application zoom zoom < 5.16.5 Yes

References