QID 378781

Date Published: 2023-08-21

QID 378781: Zoom Rooms Multiple Security Vulnerabilities (ZSB-23036, ZSB-23037)

Zoom Rooms is a software-based room system that provides an integrated experience for audio conferencing, wireless screen sharing, and video conferencing.

CVE-2023-39211: Improper privilege management in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

CVE-2023-39212: Untrusted search path in Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable a denial of service via local access.

Affected Versions:
Zoom Rooms for Windows clients before version 5.15.5

QID Detection Logic:
Windows: This authenticated QID detects vulnerable version of Zoom Rooms using registry "HKLM\SOFTWARE\Classes\zoomroom\DefaultIcon" and "HKLM\SOFTWARE\WOW6432Node\Classes\zoomroom\DefaultIcon"

Successful exploit of this vulnerability may allow an attacker to execute privileged functions and cause a local denial of service or allow an authenticated user to access sensitive information.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to upgrade to Zoom Rooms 5.15.5 or later to remediate these vulnerabilities.

    CVEs related to QID 378781

    Software Advisories
    Advisory ID Software Component Link
    ZSB-23036 URL Logo explore.zoom.us/en/trust/security/security-bulletin/
    ZSB-23037 URL Logo explore.zoom.us/en/trust/security/security-bulletin/