CVE-2023-22882: Denial of Service in Zoom Clients
Published Mar 16, 2023
·Updated
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
Affected Software
1 affected component
Zoom Zoom<5.13.5
Event History
Mar 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Zoom vulnerability?
The vulnerability ID for this Zoom vulnerability is CVE-2023-22882.
2
What is the severity of CVE-2023-22882?
The severity of CVE-2023-22882 is high (7.5).
3
How can this vulnerability be exploited?
This vulnerability can be exploited by sending specially crafted UDP traffic to a victim Zoom client.
4
How can I fix CVE-2023-22882?
To fix CVE-2023-22882, update Zoom clients to version 5.13.5 or later.
5
Is there any additional information available about CVE-2023-22882?
Yes, you can find more information about CVE-2023-22882 in the Zoom security bulletin: https://explore.zoom.us/en/trust/security/security-bulletin/