Zoom Win Client <5.14.0 Improper Privilege Management
CVE-2023-34120 Published on June 13, 2023
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Vulnerability Analysis
CVE-2023-34120 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Products Associated with CVE-2023-34120
Want to know whenever a new CVE is published for Zoom Virtual Desktop Infrastructure? stack.watch will email you.
Affected Versions
Zoom Video Communications, Inc. Zoom for Windows Client:- Version before 5.14.0 is affected.
- Version before 5.14.0 is affected.
- Version before 5.14.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.