Improper privilege management in Zoom Workplace Desktop App for Windows - CVE-2023-34120

 

Improper privilege management in Zoom Workplace Desktop App for Windows - CVE-2023-34120

Published: June 12, 2023 / Updated: June 12, 2023


Vulnerability identifier: #VU77159
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34120
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management. A local user can utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.


Affected software

Zoom Workplace Desktop App for Windows
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)

How to mitigate CVE-2023-34120

Install updates from vendor's website.

Zoom Workplace Desktop App for Windows - update to 5.14.0 13888
Zoom Rooms Client for Windows - update to 5.14.0 2683
Virtual Desktop Infrastructure (VDI) - update to 5.14.0 23370

External References

Related Security Bulletins