QID 379380
Date Published: 2024-02-21
QID 379380: Zoom Clients Improper Authentication Vulnerability (ZSB-24005)
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
Zoom has released a security update for zoom to fix the vulnerabilities.
Affected Versions:
Zoom Desktop Client for Windows before version 5.17.0
Zoom Desktop Client for macOS before version 5.17.0
Zoom Desktop Client for Linux before version 5.17.0
Zoom VDI Client for Windows before version 5.17.5 (excluding 5.15.15 and 5.16.12)
Zoom Rooms Client for Windows before version 5.17.0
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom products using registry entry for windows and firing commands in linux and macosx.
Successful exploitation of this vulnerability could lead Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information.
CVEs related to QID 379380
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-24005 |
|