Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://explore.zoom.us/en/trust/security/security-bulletin/ |
![]() ![]() |
History
Thu, 02 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 19 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-269 |
Thu, 19 Sep 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. |
Weaknesses | CWE-347 |

Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-01-02T20:10:14.414Z
Reserved: 2023-05-25T22:01:29.098Z
Link: CVE-2023-34120

Updated: 2024-08-02T16:01:54.118Z

Status : Modified
Published: 2023-06-13T18:15:21.913
Modified: 2024-11-21T08:06:35.410
Link: CVE-2023-34120

No data.