Vulnerability Description
Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local access. Users may potentially utilize higher level system privileges maintained by the Zoom client to spawn processes with escalated privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Virtual Desktop Infrastructure | < 5.14.0 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
- https://explore.zoom.us/en/trust/security/security-bulletin/Vendor Advisory
FAQ
What is CVE-2023-34120?
CVE-2023-34120 is a vulnerability with a CVSS score of 8.7 (HIGH). Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privil...
How severe is CVE-2023-34120?
CVE-2023-34120 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34120?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Virtual Desktop Infrastructure, Microsoft Windows.