Zoom Security Updates – 12 July 2023

Zoom has released security updates to fix vulnerabilities in Zoom Rooms, Zoom Windows Client, and Zoom Client SDK.

The addressed vulnerabilities could allow the attacker to escalate privileges, or disclose information on the affected systems.

Sample of the addressed vulnerabilities:

1. Zoom Rooms Improper Input Validation (CVE-2023-36538):

  • CVSS: 8.4
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Privilege Escalation

2. Zoom Desktop Improper Input Validation (CVE-2023-34116):

  • CVSS: 8.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Privilege Escalation
Vulnerabilities
  • CVE-2023-36539
  • CVE-2023-36538
  • CVE-2023-36537
  • CVE-2023-36536
  • CVE-2023-34119
  • CVE-2023-34118
  • CVE-2023-34117
  • CVE-2023-34116
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References