CVE-2023-22881: Denial of Service in Zoom Clients
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22881?
CVE-2023-22881 is a STUN parsing vulnerability found in Zoom clients before version 5.13.5.
How can a malicious actor exploit CVE-2023-22881?
A malicious actor can exploit CVE-2023-22881 by sending specially crafted UDP traffic to a victim Zoom client, causing it to crash.
What is the impact of CVE-2023-22881?
CVE-2023-22881 can result in a denial of service (DoS) situation, where the victim Zoom client crashes and becomes unresponsive.
How can I mitigate CVE-2023-22881?
To mitigate CVE-2023-22881, it is recommended to update Zoom clients to version 5.13.5 or later.
Where can I find more information about CVE-2023-22881?
You can find more information about CVE-2023-22881 in the official Zoom security bulletin: https://explore.zoom.us/en/trust/security/security-bulletin/