CVE-2023-36535: High severity zoom rooms vulnerability
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36535?
The severity of CVE-2023-36535 is high with a CVSS score of 6.5.
What is the affected software of CVE-2023-36535?
The affected software of CVE-2023-36535 includes Zoom Rooms (Android, iPad OS, macOS, Windows), Zoom Virtual Desktop Infrastructure, and Zoom (Android, iPhone OS, Linux, macOS, Windows) versions up to exclusive 5.14.10.
How can an authenticated user exploit CVE-2023-36535?
An authenticated user can exploit CVE-2023-36535 by enabling information disclosure via network access.
What is the Common Weakness Enumeration (CWE) for CVE-2023-36535?
The Common Weakness Enumeration (CWE) for CVE-2023-36535 is CWE-602.
Where can I find more information about CVE-2023-36535?
You can find more information about CVE-2023-36535 in the Zoom security bulletin: [Zoom Security Bulletin](https://explore.zoom.us/en/trust/security/security-bulletin/).