CVE Vulnerabilities

CVE-2023-49647

Incorrect Privilege Assignment

Published: Jan 12, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Meeting_software_development_kit Zoom * 5.16.10 (excluding)
Video_software_development_kit Zoom * 5.16.10 (excluding)
Zoom Zoom * 5.16.10 (excluding)

Potential Mitigations

References