8.8

CVE-2023-43582

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meetings SwPlatform android Version < 5.16.0
Zoom ≫ Meetings SwPlatform iphone_os Version < 5.16.0
Zoom ≫ Meetings SwPlatform linux Version < 5.16.0
Zoom ≫ Meetings SwPlatform macos Version < 5.16.0
Zoom ≫ Meetings SwPlatform windows Version < 5.16.0
Zoom ≫ Rooms SwPlatform android Version < 5.16.0
Zoom ≫ Rooms SwPlatform ipad_os Version < 5.16.0
Zoom ≫ Rooms SwPlatform macos Version < 5.16.0
Zoom ≫ Rooms SwPlatform windows Version < 5.16.0
Zoom ≫ Virtual Desktop Infrastructure Version < 5.14.13
Zoom ≫ Virtual Desktop Infrastructure Version >= 5.15.0 < 5.15.11
Zoom ≫ Zoom SwPlatform android Version < 5.16.0
Zoom ≫ Zoom SwPlatform iphone_os Version < 5.16.0
Zoom ≫ Zoom SwPlatform linux Version < 5.16.0
Zoom ≫ Zoom SwPlatform macos Version < 5.16.0
Zoom ≫ Zoom SwPlatform windows Version < 5.16.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.467
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@zoom.us 5.5 2.1 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-939 Improper Authorization in Handler for Custom URL Scheme

The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

https://explore.zoom.us/en/trust/security/security-bulletin/
Vendor Advisory