Code Injection in Zoom Video Communications, Inc. products - CVE-2023-28599
Published: June 12, 2023
Vulnerability identifier: #VU77151
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28599
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to improper input validation hen processing HTML code. A remote user can inject arbitrary HTML code into their display name and force the victim to visit a malicious website during the meeting creation.
Affected software
Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
How to mitigate CVE-2023-28599
Install updates from vendor's website.
Zoom Workplace App for iOS - update to 5.13.10 7012
Zoom Workplace Desktop App for Windows - update to 5.13.10 13305
Zoom Workplace Desktop App for macOS - update to 5.13.10 16307
Zoom Workplace App for Android - update to 5.13.10 12526
Zoom Workplace Desktop App for Linux - update to 5.13.10 1208
Zoom Workplace Desktop App for Windows - update to 5.13.10 13305
Zoom Workplace Desktop App for macOS - update to 5.13.10 16307
Zoom Workplace App for Android - update to 5.13.10 12526
Zoom Workplace Desktop App for Linux - update to 5.13.10 1208