QID 378781
Date Published: 2023-08-21
QID 378781: Zoom Rooms Multiple Security Vulnerabilities (ZSB-23036, ZSB-23037)
Zoom Rooms is a software-based room system that provides an integrated experience for audio conferencing, wireless screen sharing, and video conferencing.
CVE-2023-39211: Improper privilege management in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable an information disclosure via local access.
CVE-2023-39212: Untrusted search path in Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable a denial of service via local access.
Affected Versions:
Zoom Rooms for Windows clients before version 5.15.5
QID Detection Logic:
Windows: This authenticated QID detects vulnerable version of Zoom Rooms using registry "HKLM\SOFTWARE\Classes\zoomroom\DefaultIcon" and "HKLM\SOFTWARE\WOW6432Node\Classes\zoomroom\DefaultIcon"
Successful exploit of this vulnerability may allow an attacker to execute privileged functions and cause a local denial of service or allow an authenticated user to access sensitive information.
CVEs related to QID 378781
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-23036 |
|
||
| ZSB-23037 |
|