Zoom Security Updates – 13 September 2023

Zoom has released security updates to fix vulnerabilities in Zoom CleanZoom, Zoom clients, and Zoom Desktop Client for Windows and Linux.

The addressed vulnerabilities could allow the attacker to perform denial of service attacks, or gain elevated privileges on the affected systems.

Sample of the addressed vulnerabilities:

1. Zoom CleanZoom Privilege Escalation Vulnerability (CVE-2023-39201):

  • CVSS: 7.2
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: High
  • User Interaction: Required
  • Consequences: Gain Privileges

2. Zoom Clients Denial of Service Vulnerability (CVE-2023-39215):

  • CVSS: 7.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities
  • CVE-2023-39201
  • CVE-2023-39208
  • CVE-2023-39215
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References