CVE Vulnerabilities

CVE-2023-28597

Trust Boundary Violation

Published: Mar 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a users device and data, and remote code execution.

Weakness

The product mixes trusted and untrusted data in the same data structure or structured message.

Affected Software

Name Vendor Start Version End Version
Rooms Zoom * 5.13.5 (excluding)
Zoom Zoom * 5.13.5 (excluding)

References