Improper Access Control in Zoom VDI Client Installer

  • ZSB-23011
  • CVE-2023-28603
  • High
  • 7.7
  • CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • Zoom VDI Windows Meeting installer before version 5.14.0

Reported by sim0nsecurity

Revision Date Description
1.0 06/13/2023

Initial Publication