CVE-2023-49647: Zoom Desktop Client for Windows - Improper Access Control
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49647?
CVE-2023-49647 has been classified as a moderate severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2023-49647?
To mitigate CVE-2023-49647, update the Zoom Desktop Client, Zoom VDI Client, or Zoom SDKs to version 5.16.10 or later.
Who is affected by CVE-2023-49647?
CVE-2023-49647 affects users of the Zoom Desktop Client, Zoom VDI Client, and Zoom SDKs for Windows prior to version 5.16.10.
What types of attacks can exploit CVE-2023-49647?
CVE-2023-49647 can be exploited by an authenticated user to escalate privileges via local access.
When was CVE-2023-49647 disclosed?
CVE-2023-49647 was disclosed in late 2023, prompting immediate attention from affected users.