CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. | 6.5 |
Medium |
||
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. | 6.5 |
Medium |
||
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access. | 7.8 |
High |
||
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. | 8.3 |
High |