First published: Tue Aug 08 2023(Updated: )
Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
Credit: security@zoom.us security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Zoom | <5.14.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36540 is a vulnerability in the Zoom Desktop Client for Windows before version 5.14.5 that allows an authenticated user to enable an escalation of privilege via local access due to an untrusted search path in the installer.
CVE-2023-36540 affects Zoom Desktop Client for Windows before version 5.14.5 by allowing an authenticated user to enable an escalation of privilege via local access.
CVE-2023-36540 has a severity rating of 7.3 (high).
To fix CVE-2023-36540, update Zoom Desktop Client for Windows to version 5.14.5 or later.
You can find more information about CVE-2023-36540 in the Zoom Desktop Client security bulletin: https://explore.zoom.us/en/trust/security/security-bulletin/