8.8
CVE-2023-49647
- EPSS 0.04%
- Published 12.01.2024 22:15:45
- Last modified 21.11.2024 08:33:39
- Source security@zoom.us
- Teams watchlist Login
- Open Login
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
Data is provided by the National Vulnerability Database (NVD)
Zoom ≫ Meeting Software Development Kit SwPlatformwindows Version < 5.16.10
Zoom ≫ Video Software Development Kit SwPlatformwindows Version < 5.16.10
Zoom ≫ Virtual Desktop Infrastructure Version < 5.14.14
Zoom ≫ Virtual Desktop Infrastructure Version >= 5.15.0 < 5.15.12
Zoom ≫ Virtual Desktop Infrastructure Version >= 5.16.0 < 5.16.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.097 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
security@zoom.us | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.