CVE-2023-39204: Buffer Overflow
Published Nov 14, 2023
·Updated
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Affected Software
21 affected components
Zoom Meetings Android<5.15.10
Zoom Meetings Iphone Os<5.15.10
Zoom Meetings Linux<5.15.10
Zoom Meetings Macos<5.15.10
Zoom Meetings Windows<5.15.10
Zoom Rooms Android<5.15.10
Zoom Rooms Ipad Os<5.15.10
Zoom Rooms Macos<5.15.10
Zoom Rooms Windows<5.15.10
Zoom Video Software Development Kit Android<5.15.10
Zoom Video Software Development Kit Iphone Os<5.15.10
Zoom Video Software Development Kit Linux<5.15.10
Zoom Video Software Development Kit Macos<5.15.10
Zoom Video Software Development Kit Windows<5.15.10
Zoom Virtual Desktop Infrastructure<5.14.13
Zoom Virtual Desktop Infrastructure>=5.15.0<5.15.11
Zoom Zoom Android<5.15.10
Zoom Zoom Iphone Os<5.15.10
Zoom Zoom Linux<5.15.10
Zoom Zoom Macos<5.15.10
Zoom Zoom Windows<5.15.10
Event History
Nov 14, 2023
CVE Published
10:28 PM
Data Sourced
10:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-39204?
CVE-2023-39204 is a vulnerability that allows an unauthenticated user to conduct a denial of service attack on some Zoom clients.
2
How severe is CVE-2023-39204?
CVE-2023-39204 has a severity rating of 7.5 (high).
3
Which software versions are affected by CVE-2023-39204?
Zoom Meetings, Zoom Rooms, Zoom Video Software Development Kit, and Zoom Virtual Desktop Infrastructure versions up to 5.15.10 are affected.
4
How can an unauthenticated user exploit CVE-2023-39204?
An unauthenticated user can exploit CVE-2023-39204 by conducting a denial of service attack via network access.
5
Where can I find more information about CVE-2023-39204?
You can find more information about CVE-2023-39204 at the following link: [Zoom Security Bulletin](https://explore.zoom.us/en/trust/security/security-bulletin/)