7.5

CVE-2023-39204

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

Data is provided by the National Vulnerability Database (NVD)
ZoomMeetings SwPlatformandroid Version < 5.15.10
ZoomMeetings SwPlatformiphone_os Version < 5.15.10
ZoomMeetings SwPlatformlinux Version < 5.15.10
ZoomMeetings SwPlatformmacos Version < 5.15.10
ZoomMeetings SwPlatformwindows Version < 5.15.10
ZoomRooms SwPlatformandroid Version < 5.15.10
ZoomRooms SwPlatformipad_os Version < 5.15.10
ZoomRooms SwPlatformmacos Version < 5.15.10
ZoomRooms SwPlatformwindows Version < 5.15.10
ZoomVideo Software Development Kit SwPlatformandroid Version < 5.15.10
ZoomVideo Software Development Kit SwPlatformiphone_os Version < 5.15.10
ZoomVideo Software Development Kit SwPlatformlinux Version < 5.15.10
ZoomVideo Software Development Kit SwPlatformmacos Version < 5.15.10
ZoomVideo Software Development Kit SwPlatformwindows Version < 5.15.10
ZoomVirtual Desktop Infrastructure Version < 5.14.13
ZoomVirtual Desktop Infrastructure Version >= 5.15.0 < 5.15.11
ZoomZoom SwPlatformandroid Version < 5.15.10
ZoomZoom SwPlatformiphone_os Version < 5.15.10
ZoomZoom SwPlatformlinux Version < 5.15.10
ZoomZoom SwPlatformmacos Version < 5.15.10
ZoomZoom SwPlatformwindows Version < 5.15.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.503
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@zoom.us 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.