First published: Tue Nov 14 2023(Updated: )
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Virtual Desktop Infrastructure | <5.14.13 | |
Zoom Virtual Desktop Infrastructure | >=5.15.0<5.15.11 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-39199 is medium with a severity value of 6.5.
Zoom Meetings (Android, iPhone OS, Linux, macOS, Windows), Zoom Rooms (Android, iPad OS, macOS, Windows), Zoom Virtual Desktop Infrastructure, Zoom Zoom (Android, iPhone OS, Linux, macOS, Windows).
The vulnerability in CVE-2023-39199 is due to cryptographic issues in the In-Meeting Chat feature of some Zoom clients, which may allow a privileged user to conduct an information disclosure via network access.
To fix CVE-2023-39199, it is recommended to update Zoom Meetings, Zoom Rooms, and Zoom Virtual Desktop Infrastructure to version 5.16.0 or above.
You can find more information about CVE-2023-39199 in the Zoom security bulletin available at https://explore.zoom.us/en/trust/security/security-bulletin/