CVE-2023-39217: Input Validation
Published Aug 8, 2023
·Updated
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.
Affected Software
10 affected components
Zoom Meeting Software Development Kit Android<5.14.10
Zoom Meeting Software Development Kit Iphone Os<5.14.10
Zoom Meeting Software Development Kit Linux<5.14.10
Zoom Meeting Software Development Kit Macos<5.14.10
Zoom Meeting Software Development Kit Windows<5.14.10
Zoom Video Software Development Kit Android<5.14.10
Zoom Video Software Development Kit Iphone Os<5.14.10
Zoom Video Software Development Kit Linux<5.14.10
Zoom Video Software Development Kit Macos<5.14.10
Zoom Video Software Development Kit Windows<5.14.10
Event History
Aug 8, 2023
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-39217?
CVE-2023-39217 is a vulnerability in Zoom SDK’s before version 5.14.10 that allows an unauthenticated user to enable a denial of service via network access.
2
What is the severity of CVE-2023-39217?
CVE-2023-39217 has a severity rating of 7.5 (High).
3
What is affected by CVE-2023-39217?
Zoom Meeting Software Development Kit and Zoom Video Software Development Kit versions up to 5.14.10 are affected by CVE-2023-39217.
4
How can an unauthenticated user exploit CVE-2023-39217?
An unauthenticated user can exploit CVE-2023-39217 by enabling a denial of service via network access.
5
How can I fix CVE-2023-39217?
To fix CVE-2023-39217, Zoom users should update their Zoom SDK to version 5.14.10 or later.