7.8

CVE-2023-49647

Zoom Desktop Client for Windows - Improper Access Control

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meeting Software Development Kit SwPlatform windows Version < 5.16.10
Zoom ≫ Video Software Development Kit SwPlatform windows Version < 5.16.10
Zoom ≫ Zoom SwPlatform windows Version < 5.16.10
Zoom ≫ Virtual Desktop Infrastructure Version < 5.14.14
   Microsoft ≫ Windows Version -
Zoom ≫ Virtual Desktop Infrastructure Version >= 5.15.0 < 5.15.12
   Microsoft ≫ Windows Version -
Zoom ≫ Virtual Desktop Infrastructure Version >= 5.16.0 < 5.16.10
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.156
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@zoom.us 8.8 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/
Vendor Advisory