First published: Tue Nov 14 2023(Updated: )
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.15.10 | |
Zoom Meetings | <5.15.10 | |
Zoom Meetings | <5.15.10 | |
Zoom Meetings | <5.15.10 | |
Zoom Meetings | <5.15.10 | |
Zoom Rooms | <5.15.10 | |
Zoom Rooms | <5.15.10 | |
Zoom Rooms | <5.15.10 | |
Zoom Rooms | <5.15.10 | |
Zoom Video Software Development Kit | <5.15.10 | |
Zoom Video Software Development Kit | <5.15.10 | |
Zoom Video Software Development Kit | <5.15.10 | |
Zoom Video Software Development Kit | <5.15.10 | |
Zoom Video Software Development Kit | <5.15.10 | |
Zoom Virtual Desktop Infrastructure | <5.14.13 | |
Zoom Virtual Desktop Infrastructure | >=5.15.0<5.15.11 | |
Zoom Zoom | <5.15.10 | |
Zoom Zoom | <5.15.10 | |
Zoom Zoom | <5.15.10 | |
Zoom Zoom | <5.15.10 | |
Zoom Zoom | <5.15.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39204 is a vulnerability that allows an unauthenticated user to conduct a denial of service attack on some Zoom clients.
CVE-2023-39204 has a severity rating of 7.5 (high).
Zoom Meetings, Zoom Rooms, Zoom Video Software Development Kit, and Zoom Virtual Desktop Infrastructure versions up to 5.15.10 are affected.
An unauthenticated user can exploit CVE-2023-39204 by conducting a denial of service attack via network access.
You can find more information about CVE-2023-39204 at the following link: [Zoom Security Bulletin](https://explore.zoom.us/en/trust/security/security-bulletin/)