CVE-2023-36536: High severity zoom rooms vulnerability
Published Jul 11, 2023
·Updated
Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
Affected Software
1 affected component
Zoom Rooms Windows<5.15.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoom Rooms for Windowsto a version that resolves this vulnerability.Fixed in 5.15.0
Event History
Jul 11, 2023
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-36536.
2
What is the severity of CVE-2023-36536?
The severity of CVE-2023-36536 is high with a severity value of 7.
3
What is the affected software?
The affected software is Zoom Rooms for Windows before version 5.15.0.
4
How can an authenticated user exploit this vulnerability?
An authenticated user can exploit this vulnerability via local access to enable an escalation of privilege.
5
How can I fix CVE-2023-36536?
To fix CVE-2023-36536, update Zoom Rooms for Windows to version 5.15.0 or later.