CVE-2023-39218: Medium severity zoom rooms vulnerability
Published Aug 8, 2023
·Updated
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.
Affected Software
10 affected components
Zoom Rooms Android<5.14.10
Zoom Rooms Ipad Os<5.14.10
Zoom Rooms Macos<5.14.10
Zoom Rooms Windows<5.14.10
Zoom Virtual Desktop Infrastructure<5.14.10
Zoom Zoom Android<5.14.10
Zoom Zoom Iphone Os<5.14.10
Zoom Zoom Linux<5.14.10
Zoom Zoom Macos<5.14.10
Zoom Zoom Windows<5.14.10
Event History
Aug 8, 2023
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-39218?
CVE-2023-39218 is a vulnerability in Zoom clients before version 5.14.10 that allows a privileged user to enable information disclosure via network access.
2
Which software versions are affected by CVE-2023-39218?
CVE-2023-39218 affects Zoom Rooms (Android, iPad OS, macOS, and Windows) and Zoom Virtual Desktop Infrastructure before version 5.14.10.
3
What is the severity of CVE-2023-39218?
CVE-2023-39218 has a severity rating of 4.9, which is considered medium.
4
How can a privileged user exploit CVE-2023-39218?
A privileged user can exploit CVE-2023-39218 by enabling information disclosure via network access.
5
How can I fix CVE-2023-39218?
To fix CVE-2023-39218, it is recommended to update Zoom clients to version 5.14.10 or later.