Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49647


Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.


Published

2024-01-12T22:15:45.130

Last Modified

2024-11-21T08:33:39.630

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-266
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zoom meeting_software_development_kit < 5.16.10 Yes
Application zoom video_software_development_kit < 5.16.10 Yes
Application zoom zoom < 5.16.10 Yes
Application zoom virtual_desktop_infrastructure < 5.14.14 Yes
Application zoom virtual_desktop_infrastructure < 5.15.12 Yes
Application zoom virtual_desktop_infrastructure < 5.16.10 Yes
Operating System microsoft windows - No

References