QID 379176

Date Published: 2024-02-19

QID 379176: Zoom Desktop Client and VDI Uncontrolled Resource Consumption Vulnerability (ZSB-23047)

Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
CVE-2023-39203: Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

Affected Versions:
Zoom Desktop Client for Windows before version 5.16.0
Zoom VDI Client before version 5.16.0 (excluding 5.14.13 and 5.15.11)

QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom Client and VDI for affected versions (Windows and macOS)

On successful exploitation an authenticated attacker to disclose sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to Zoom Client 5.16.5 or later to remediate these vulnerabilities.
    For more information kindly visit ZSB-23047

    CVEs related to QID 379176

    Software Advisories
    Advisory ID Software Component Link
    ZSB-23047 URL Logo www.zoom.com/en/trust/security-bulletin/ZSB-23047/