LOW · 3.1

CVE-2023-39202

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

Vulnerability Description

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

CVSS Score

3.1

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ZoomRooms< 5.16.0
ZoomVirtual Desktop Infrastructure< 5.14.13

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-39202?

CVE-2023-39202 is a vulnerability with a CVSS score of 3.1 (LOW). Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

How severe is CVE-2023-39202?

CVE-2023-39202 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-39202?

Check the references section above for vendor advisories and patch information. Affected products include: Zoom Rooms, Zoom Virtual Desktop Infrastructure.