QID 378780

Date Published: 2023-08-21

QID 378780: Zoom Client, VDI Escalation Privilege Vulnerability (ZSB-23038)

Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.

Affected Versions:
Zoom for Windows clients before version 5.15.2
Zoom VDI Windows Meeting clients before version 5.15.2
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom Client, VDI prior to version 5.15.2(Windows)

Users may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to upgrade to Zoom Client 5.15.2(Windows) or later to remediate these vulnerabilities.

    CVEs related to QID 378780

    Software Advisories
    Advisory ID Software Component Link
    ZSB-23038 URL Logo explore.zoom.us/en/trust/security/security-bulletin/