CVE-2023-34120: High severity Zoom Virtual Desktop Infrastructure vulnerability
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoom for Windows / Zoom Rooms for Windows / Zoom VDI for Windowsto a version that resolves this vulnerability.Fixed in 5.14.0
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2023-34120
What is the severity of CVE-2023-34120?
The severity of CVE-2023-34120 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2023-34120?
Zoom Virtual Desktop Infrastructure versions up to and excluding 5.14.0 are affected by CVE-2023-34120.
How can an authenticated user potentially enable an escalation of privilege via local access in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows?
Due to improper privilege management, an authenticated user could potentially enable an escalation of privilege via local access in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients.
Is Microsoft Windows affected by CVE-2023-34120?
No, Microsoft Windows is not affected by CVE-2023-34120.
How can I fix CVE-2023-34120?
To fix CVE-2023-34120, users should update Zoom Virtual Desktop Infrastructure to version 5.14.0 or higher.
Where can I find more information about CVE-2023-34120?
More information about CVE-2023-34120 can be found in the Zoom security bulletin: https://explore.zoom.us/en/trust/security/security-bulletin/