Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32267 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. |
| Link | Providers |
|---|---|
| https://explore.zoom.us/en/trust/security/security-bulletin/ |
|
Wed, 19 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-02-19T15:27:48.810Z
Reserved: 2023-03-17T00:00:00.000Z
Link: CVE-2023-28597
Updated: 2024-08-02T13:43:22.755Z
Status : Modified
Published: 2023-03-27T21:15:12.260
Modified: 2025-02-19T16:15:37.990
Link: CVE-2023-28597
No data.
OpenCVE Enrichment
No data.
EUVD