CVE Vulnerabilities

CVE-2023-49647

Incorrect Privilege Assignment

Published: Jan 12, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Meeting_software_development_kitZoom*5.16.10 (excluding)
Video_software_development_kitZoom*5.16.10 (excluding)
ZoomZoom*5.16.10 (excluding)

Potential Mitigations

References