Code Injection in Zoom Workplace Desktop App for Windows and Virtual Desktop Infrastructure (VDI) - CVE-2023-39213
Published: August 8, 2023
Vulnerability identifier: #VU79132
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39213
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the target system.
Affected software
Zoom Workplace Desktop App for Windows
Virtual Desktop Infrastructure (VDI)
Virtual Desktop Infrastructure (VDI)
How to mitigate CVE-2023-39213
Install updates from vendor's website.
Zoom Workplace Desktop App for Windows - update to 5.15.2 18096
Virtual Desktop Infrastructure (VDI) - update to 5.15.2 23760
Virtual Desktop Infrastructure (VDI) - update to 5.15.2 23760