QID 378784

Date Published: 2023-08-22

QID 378784: Zoom Rooms Information Disclosure Vulnerability (ZSB-23034, ZSB-23031)

Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.

Zoom Rooms prior to 5.14.10 contain Client-side enforcement of server-side security issue for Zoom Desktop Client for Windows, Linux and macOS.

Affected Versions:
Zoom Rooms for Windows and macOS before version 5.14.10 QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom Rooms prior to version 5.14.10 (Windows and macOS).

Successful exploitation of this vulnerability may allow a privileged user to enable information disclosure via network access.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 7.7 severity.
  • Solution
    Customers are advised to upgrade to Zoom Rooms 5.14.10 or later to remediate these vulnerabilities.

    CVEs related to QID 378784

    Software Advisories
    Advisory ID Software Component Link
    ZSB-23031 URL Logo explore.zoom.us/en/trust/security/security-bulletin/
    ZSB-23034 URL Logo explore.zoom.us/en/trust/security/security-bulletin/