MEDIUM🇵🇱 Wersja polska

CVE-2023-43582

CVSS 5.5v3.1pub. 2023-11-15upd. 2024-11-21

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
  • Zoom Meetings

    APP
    Zoom
    < 5.16.0
  • Zoom Rooms

    APP
    Zoom
    < 5.16.0
  • Zoom Virtual Desktop Infrastructure

    APP
    Zoom
    < 5.14.135.15.0 – 5.15.11 (excl.)
  • Zoom

    APP
    Zoom
    < 5.16.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-49457CRITICAL9.6PL ✓same product

Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć

CVE-2024-24691CRITICAL9.6PL ✓same product

Privilege escalation w Zoom Desktop Client, VDI Client i Meeting SDK dla Windows

CVE-2023-39213CRITICAL9.6PL ✓same product

Zoom Desktop Client i VDI Client — privilege escalation przez sieć

CVE-2023-36534CRITICAL9.3PL ✓same product

Path traversal w Zoom Desktop Client dla Windows — eskalacja uprawnień

CVE-2023-39216CRITICAL9.6PL ✓same product

Nieprawidłowa walidacja danych wejściowych w Zoom Desktop Client dla Windows — privilege escalation