8.8

CVE-2023-49647

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.

Data is provided by the National Vulnerability Database (NVD)
ZoomMeeting Software Development Kit SwPlatformwindows Version < 5.16.10
ZoomVideo Software Development Kit SwPlatformwindows Version < 5.16.10
ZoomZoom SwPlatformwindows Version < 5.16.10
ZoomVirtual Desktop Infrastructure Version < 5.14.14
   MicrosoftWindows Version-
ZoomVirtual Desktop Infrastructure Version >= 5.15.0 < 5.15.12
   MicrosoftWindows Version-
ZoomVirtual Desktop Infrastructure Version >= 5.16.0 < 5.16.10
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.097
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@zoom.us 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.