QID 378715
Date Published: 2023-08-01
QID 378715: Zoom Rooms Multiple Vulnerabilities (ZSB-23021, ZSB-23022 and ZSB-23024)
Zoom Rooms is a software-based room system that provides an integrated experience for audio conferencing, wireless screen sharing, and video conferencing.
CVE-2023-34119: Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
CVE-2023-36536:Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
CVE-2023-36538: Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
Affected Versions:
Zoom Rooms for Windows clients before version 5.15.0
QID Detection Logic:
Windows: This authenticated QID detects vulnerable version of Zoom Rooms using registry "HKLM\SOFTWARE\Classes\zoomroom\DefaultIcon" and "HKLM\SOFTWARE\WOW6432Node\Classes\zoomroom\DefaultIcon"
Successful exploitation of this vulnerability may allows an authenticated user to enable an escalation of privilege via local access.
- ZSB-23021, ZSB-23022, ZSB-23024 -
explore.zoom.us/en/trust/security/security-bulletin/
CVEs related to QID 378715
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-23021 |
|
||
| ZSB-23022 |
|
||
| ZSB-23024 |
|