← back
CVE-2023-34116highCWE-78

CVE-2023-34116

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.2epss 1.0%
exploitation probability
1.0%top 42% of all CVEs
observed exploitation
nono source reports it
In short

The Zoom Desktop Client for Windows before version 5.15.0 fails to properly validate user input, which could allow an attacker on the network to gain elevated privileges on the system.

Technical detail

CWE-78 (OS Command Injection) via improper input validation in Zoom Desktop Client for Windows <5.15.0 enables privilege escalation through network-accessible vectors. Attack requires network access but not prior authentication; successful exploitation grants elevated system privileges.

Summary generated and translated by AI from the official description.
Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H