CVE-2023-49646: Medium severity zoom meeting sdk vulnerability
Published Dec 13, 2023
·Updated
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
Affected Software
9 affected components
Zoom Meeting Software Development Kit<5.16.5
Zoom Video Software Development Kit<5.16.5
Zoom Virtual Desktop Infrastructure<5.14.14
Zoom Virtual Desktop Infrastructure>=5.15.0<5.15.12
Zoom Zoom Android<5.16.5
Zoom Zoom Iphone Os<5.16.5
Zoom Zoom Linux<5.16.5
Zoom Zoom Macos<5.16.5
Zoom Zoom Windows<5.16.5
Event History
Dec 13, 2023
CVE Published
10:19 PM
Data Sourced
10:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49646?
CVE-2023-49646 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-49646?
To fix CVE-2023-49646, upgrade your Zoom client to version 5.16.5 or later.
3
What types of software are affected by CVE-2023-49646?
CVE-2023-49646 impacts various Zoom clients, including Meeting SDK, Video SDK, and different platforms like Android and Windows, all prior to version 5.16.5.
4
Can CVE-2023-49646 be exploited remotely?
Yes, CVE-2023-49646 can be exploited via network access by an authenticated user.
5
What impact does CVE-2023-49646 have on users?
CVE-2023-49646 may allow an authenticated user to conduct a denial of service attack.