Code Injection in Zoom Video Communications, Inc. products - CVE-2023-28599

 

Code Injection in Zoom Video Communications, Inc. products - CVE-2023-28599

Published: June 12, 2023


Vulnerability identifier: #VU77151
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28599
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform spoofing attack.

The vulnerability exists due to improper input validation hen processing HTML code. A remote user can inject arbitrary HTML code into their display name and force the victim to visit a malicious website during the meeting creation.


Affected software

Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux

How to mitigate CVE-2023-28599

Install updates from vendor's website.

Zoom Workplace App for iOS - update to 5.13.10 7012
Zoom Workplace Desktop App for Windows - update to 5.13.10 13305
Zoom Workplace Desktop App for macOS - update to 5.13.10 16307
Zoom Workplace App for Android - update to 5.13.10 12526
Zoom Workplace Desktop App for Linux - update to 5.13.10 1208

External References

Related Security Bulletins