First published: Tue Sep 12 2023(Updated: )
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.
Credit: security@zoom.us security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting Software Development Kit | <5.15.5 | |
Zoom Virtual Desktop Infrastructure | <5.14.12 | |
Zoom Virtual Desktop Infrastructure | >=5.15.0<5.15.4 | |
Zoom Zoom | <5.15.5 | |
Zoom Zoom | <5.15.5 | |
Zoom Zoom | <5.15.5 | |
Zoom Zoom | <5.15.5 | |
Zoom Zoom | <5.15.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39215 is a vulnerability that allows an authenticated user to conduct a denial of service via network access in Zoom clients.
Zoom Meeting Software Development Kit version up to 5.15.5, Zoom Virtual Desktop Infrastructure versions up to 5.14.12 and versions between 5.15.0 and 5.15.4, Zoom app versions up to 5.15.5 for Android, iPhone OS, Linux, macOS, and Windows are affected by CVE-2023-39215.
CVE-2023-39215 has a severity rating of high (6.5).
To fix CVE-2023-39215, it is recommended to update Zoom Meeting Software Development Kit, Zoom Virtual Desktop Infrastructure, and the Zoom app to versions that are not affected by the vulnerability.
You can find more information about CVE-2023-39215 at the following link: https://explore.zoom.us/en/trust/security/security-bulletin/