Privilege escalation in CleanZoom



Published: 2023-09-13
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-39201
CWE-ID CWE-426
Exploitation vector Local
Public exploit N/A
Vulnerable software
Subscribe
CleanZoom
Client/Desktop applications / Software for system administration

Vendor

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Untrusted search path

EUVDB-ID: #VU80711

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2023-39201

CWE-ID:

Exploit availability:

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an untrusted search path. A local user can place a malicious binary into a specific location on the system and execute arbitrary code with escalated privileges.

Mitigation

Install updates from vendor's website.

The vulnerability affects all versions downloaded before 24.07.2023.

Vulnerable software versions

CleanZoom: before 1.0.0.143

Fixed software versions

CPE2.3 External links

http://explore.zoom.us/en/trust/security/security-bulletin/#ZSB-23045


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###