Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38222 | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. |
| Link | Providers |
|---|---|
| https://explore.zoom.us/en/trust/security/security-bulletin/ |
|
Thu, 02 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Thu, 19 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. |
| Weaknesses | CWE-347 |
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-01-02T20:10:14.414Z
Reserved: 2023-05-25T22:01:29.098Z
Link: CVE-2023-34120
Updated: 2024-08-02T16:01:54.118Z
Status : Modified
Published: 2023-06-13T18:15:21.913
Modified: 2024-11-21T08:06:35.410
Link: CVE-2023-34120
No data.
OpenCVE Enrichment
No data.
EUVD