CVE-2023-28602: High severity zoom vulnerability
Published Jun 13, 2023
·Updated
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.
Affected Software
1 affected component
Zoom Zoom Windows<5.13.5
Event History
Jun 13, 2023
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability in Zoom for Windows clients prior to 5.13.5?
The vulnerability is an improper verification of cryptographic signature vulnerability.
2
How can a malicious user exploit this vulnerability?
A malicious user may potentially downgrade Zoom Client components to previous versions.
3
What is the severity of CVE-2023-28602?
The severity of CVE-2023-28602 is high with a CVSS score of 7.7.
4
How can I fix the vulnerability in Zoom for Windows clients?
To fix the vulnerability, update Zoom for Windows clients to version 5.13.5 or newer.
5
Where can I find more information about CVE-2023-28602?
You can find more information about CVE-2023-28602 in the Zoom security bulletin.