Improper privilege management in Zoom Workplace Desktop App for Windows - CVE-2023-34120
Published: June 12, 2023 / Updated: June 12, 2023
Vulnerability identifier: #VU77159
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34120
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management. A local user can utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
Affected software
Zoom Workplace Desktop App for Windows
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
How to mitigate CVE-2023-34120
Install updates from vendor's website.
Zoom Workplace Desktop App for Windows - update to 5.14.0 13888
Zoom Rooms Client for Windows - update to 5.14.0 2683
Virtual Desktop Infrastructure (VDI) - update to 5.14.0 23370
Zoom Rooms Client for Windows - update to 5.14.0 2683
Virtual Desktop Infrastructure (VDI) - update to 5.14.0 23370