{"api_version":"1","generated_at":"2026-07-23T13:58:28+00:00","cve":"CVE-2023-34121","urls":{"html":"https://cve.report/CVE-2023-34121","api":"https://cve.report/api/cve/CVE-2023-34121.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-34121","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-34121"},"summary":{"title":"CVE-2023-34121","description":"Improper input validation  in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting  clients before 5.14.0  may allow an authenticated user to potentially enable an escalation of privilege  via network access.","state":"PUBLIC","assigner":"security@zoom.us","published_at":"2023-06-13 18:15:00","updated_at":"2023-06-21 20:54:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://explore.zoom.us/en/trust/security/security-bulletin/","name":"https://explore.zoom.us/en/trust/security/security-bulletin/","refsource":"MISC","tags":[],"title":"Security Bulletins | Zoom","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-34121","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34121","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"34121","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"34121","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"rooms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"34121","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"virtual_desktop_infrastructure","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"34121","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"zoom","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-34121","qid":"378582","title":"Zoom Client, VDI and Rooms Improper Input Validation Vulnerability (ZSB-23013)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-34121","ASSIGNER":"security@zoom.us","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":" Improper input validation  in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting  clients before 5.14.0  may allow an authenticated user to potentially enable an escalation of privilege  via network access."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20 Improper Input Validation","cweId":"CWE-20"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Zoom Video Communications, Inc.","product":{"product_data":[{"product_name":"Zoom for Windows","version":{"version_data":[{"version_affected":"=","version_value":"before 5.14.0"}]}},{"product_name":"Zoom Rooms Client for Windows","version":{"version_data":[{"version_affected":"=","version_value":"before 5.14.0"}]}}]}},{"vendor_name":"ZoomZoom Video Communications, Inc.","product":{"product_data":[{"product_name":"Zoom VDI for Windows Meeting Clients","version":{"version_data":[{"version_affected":"=","version_value":"before 5.14.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://explore.zoom.us/en/trust/security/security-bulletin/","refsource":"MISC","name":"https://explore.zoom.us/en/trust/security/security-bulletin/"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","version":"3.1"}]}},"nvd":{"publishedDate":"2023-06-13 18:15:00","lastModifiedDate":"2023-06-21 20:54:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*","versionEndExcluding":"5.14.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*","versionEndExcluding":"5.14.0","cpe_name":[]}]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:virtual_desktop_infrastructure:*:*:*:*:*:*:*:*","versionEndExcluding":"5.14.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}