Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://explore.zoom.us/en/trust/security/security-bulletin/ |
History
Thu, 19 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-269 |
Thu, 19 Sep 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges. |
Weaknesses | CWE-347 |
MITRE
Status: PUBLISHED
Assigner: Zoom
Published: 2023-06-13T17:38:52.940Z
Updated: 2024-09-19T19:32:54.852Z
Reserved: 2023-05-25T22:01:29.098Z
Link: CVE-2023-34120
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-06-13T18:15:21.913
Modified: 2024-11-21T08:06:35.410
Link: CVE-2023-34120
Redhat
No data.