CVE Vulnerabilities

CVE-2023-36535

The UI Performs the Wrong Action

Published: Aug 08, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

Weakness

The UI performs the wrong action with respect to the user’s request.

Affected Software

Name Vendor Start Version End Version
Rooms Zoom * 5.14.10 (excluding)
Virtual_desktop_infrastructure Zoom * 5.14.10 (excluding)
Zoom Zoom * 5.14.10 (excluding)

Potential Mitigations

References