CVE-2023-36532
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 1.5%
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
In short
A buffer overflow vulnerability in older versions of Zoom allows an attacker on the network to crash the application and prevent users from using it, without needing to log in.
Technical detail
CWE-122 buffer overflow in Zoom Clients prior to 5.14.5 can be exploited by an unauthenticated attacker with network access to trigger a denial of service condition. The vulnerability requires no authentication or user interaction, affecting availability through memory corruption.
Summary generated and translated by AI from the official description.
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Zoom Video Communications, Inc. · Zoom Clients