← Retour aux CVEs
CVE-2023-34120
HIGH8.7
Description
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Details CVE
Score CVSS v3.18.7
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie6/13/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
microsoft:windowszoom:virtual_desktop_infrastructure
Faiblesses (CWE)
CWE-347
References
https://explore.zoom.us/en/trust/security/security-bulletin/(security@zoom.us)
https://explore.zoom.us/en/trust/security/security-bulletin/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.