CVE Vulnerabilities

CVE-2023-43588

The UI Performs the Wrong Action

Published: Nov 15, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

Weakness

The UI performs the wrong action with respect to the user’s request.

Affected Software

Name Vendor Start Version End Version
Meetings Zoom * 5.16.0 (excluding)
Virtual_desktop_infrastructure Zoom * 5.14.13 (excluding)
Virtual_desktop_infrastructure Zoom 5.15.0 (including) 5.15.11 (excluding)
Zoom Zoom * 5.16.0 (excluding)

Potential Mitigations

References