CVE-2023-39214: Infoleak
Published Aug 8, 2023
·Updated
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
Affected Software
14 affected components
Zoom Meeting Software Development Kit Linux<5.15.5
Zoom Meeting Software Development Kit Macos<5.15.5
Zoom Meeting Software Development Kit Windows<5.15.5
Zoom Rooms Android<5.15.5
Zoom Rooms Ipad Os<5.15.5
Zoom Rooms Macos<5.15.5
Zoom Rooms Windows<5.15.5
Zoom Zoom Android<5.15.5
Zoom Zoom Iphone Os<5.15.5
Zoom Zoom Linux<5.15.5
Zoom Zoom Macos<5.15.5
Zoom Zoom Windows<5.15.5
Zoom Meeting Software Development Kit Android<5.15.5
Zoom Meeting Software Development Kit Iphone Os<5.15.5
Event History
Aug 8, 2023
CVE Published
via MITRE·09:38 PM
Data Sourced
via MITRE·09:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-39214?
CVE-2023-39214 is a vulnerability that allows an authenticated user to enable a denial of service via network access in Zoom Client SDK's before version 5.15.5.
2
How does CVE-2023-39214 impact Zoom Client SDK?
CVE-2023-39214 exposes sensitive information and allows an authenticated user to enable a denial of service through network access.
3
Which versions of Zoom Client SDK are affected by CVE-2023-39214?
Zoom Client SDK versions before 5.15.5 are affected by CVE-2023-39214.
4
What is the severity of CVE-2023-39214?
CVE-2023-39214 has a severity rating of 8.1, which is considered high.
5
How can I fix the CVE-2023-39214 vulnerability?
To fix the CVE-2023-39214 vulnerability, update your Zoom Client SDK to version 5.15.5 or higher.