First published: Tue Nov 14 2023(Updated: )
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Meetings | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Rooms | <5.16.0 | |
Zoom Video Software Development Kit | <1.9.0 | |
Zoom Video Software Development Kit | <1.9.0 | |
Zoom Video Software Development Kit | <1.9.0 | |
Zoom Video Software Development Kit | <1.9.0 | |
Zoom Video Software Development Kit | <1.9.0 | |
Zoom Virtual Desktop Infrastructure | <5.14.13 | |
Zoom Virtual Desktop Infrastructure | >=5.15.0<5.15.11 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 | |
Zoom Zoom | <5.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39206 is a vulnerability that allows an unauthenticated user to conduct a denial of service attack on some Zoom clients via network access.
Zoom Meetings versions up to 5.16.0, Zoom Rooms versions up to 5.16.0, Zoom Video Software Development Kit versions up to 1.9.0, and Zoom Virtual Desktop Infrastructure versions up to 5.15.11 are affected by CVE-2023-39206.
The severity of CVE-2023-39206 is high, with a severity value of 7.5.
An unauthenticated user can exploit CVE-2023-39206 by conducting a denial of service attack through network access.
You can find more information about CVE-2023-39206 on the Zoom Security Bulletin page at https://explore.zoom.us/en/trust/security/security-bulletin/