← back
CVE-2023-39216criticalCWE-80

CVE-2023-39216

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.6epss 1.1%
exploitation probability
1.1%top 39% of all CVEs
observed exploitation
nono source reports it
In short

Zoom Desktop Client for Windows before version 5.14.7 has a flaw that fails to properly check user input, allowing someone on the network to gain higher privileges without needing to log in first.

Technical detail

Improper input validation in Zoom Desktop Client for Windows (pre-5.14.7) enables privilege escalation via network access without authentication. The vulnerability stems from insufficient validation of user-supplied input (CWE-80), allowing an unauthenticated attacker on the network to exploit the flaw and elevate their privileges on the affected system.

Summary generated and translated by AI from the official description.
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H