Improper access control in Zoom Clients

  • ZSB-23008
  • CVE-2023-28600
  • Medium
  • 6.6
  • CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

Zoom for macOS clients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • Zoom for macOS clients before version 5.14.0

Reported by Koh M. Nakagawa (@tsunek0h)

Revision Date Description
1.0 06/13/2023

Initial Publication