First published: Tue Jun 13 2023(Updated: )
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
Credit: security@zoom.us security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Virtual Desktop Infrastructure | <5.14.0 | |
Microsoft Windows | ||
All of | ||
Zoom Virtual Desktop Infrastructure | <5.14.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28603 is a vulnerability in the Zoom VDI client installer prior to version 5.14.0 that allows a malicious user to delete local files without proper permissions.
CVE-2023-28603 impacts Zoom VDI client installer by allowing a malicious user to delete local files without proper permissions.
The severity of CVE-2023-28603 is high with a CVSS score of 7.1.
To fix CVE-2023-28603, update Zoom VDI client installer to version 5.14.0 or later.
You can find more information about CVE-2023-28603 in the Zoom Security Bulletin at https://explore.zoom.us/en/trust/security/security-bulletin/