QID 378716
Date Published: 2023-08-01
QID 378716: Zoom Rooms Improper Privilege Management Vulnerabilities (ZSB-23020,ZSB-23023)
Zoom Rooms is a software-based room system that provides an integrated experience for audio conferencing, wireless screen sharing, and video conferencing.
CVE-2023-36537:Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
CVE-2023-34118: Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
Affected Versions:
Zoom Rooms for Windows clients before version 5.14.5
QID Detection Logic:
Windows: This authenticated QID detects vulnerable version of Zoom Rooms using registry "HKLM\SOFTWARE\Classes\zoomroom\DefaultIcon" and "HKLM\SOFTWARE\WOW6432Node\Classes\zoomroom\DefaultIcon"
Successful exploitation of this vulnerability may allow an authenticated user to enable an escalation of privilege via local access.
- ZSB-23020, ZSB-23023 -
explore.zoom.us/en/trust/security/security-bulletin/
CVEs related to QID 378716
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-23020 |
|
||
| ZSB-23023 |
|