CVE-2023-28600: Medium severity zoom vulnerability
Published Jun 13, 2023
·Updated
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.
Affected Software
1 affected component
Zoom Zoom Macos<5.14.0
Event History
Jun 13, 2023
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28600.
2
Which software is affected by this vulnerability?
Zoom for MacOS clients prior to version 5.14.0 is affected.
3
What is the impact of this vulnerability?
A malicious user may be able to delete/replace Zoom Client files, potentially causing a loss of integrity and availability to the Zoom Client.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium, with a CVSS score of 5.4.
5
How can I fix this vulnerability?
To fix this vulnerability, update your Zoom Client to version 5.14.0 or newer.