Zoom
Zoom Virtual Desktop Infrastructure: vulnerabilidades y CVE
Zoom Virtual Desktop Infrastructure tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-49647 | Alta (7.8) | 0.25% | — | 12 ene 2024 | Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local… |
| CVE-2023-49646 | Media (6.5) | 0.40% | — | 13 dic 2023 | Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2023-43586 | Alta (8.8) | 0.99% | — | 13 dic 2023 | Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access. |
| CVE-2023-43588 | Media (6.5) | 0.65% | — | 15 nov 2023 | Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. |
| CVE-2023-43582 | Alta (8.8) | 0.66% | — | 15 nov 2023 | Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
| CVE-2023-39206 | Alta (7.5) | 1.1% | — | 14 nov 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2023-39205 | Media (6.5) | 0.85% | — | 14 nov 2023 | Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2023-39204 | Alta (7.5) | 1.1% | — | 14 nov 2023 | Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
| CVE-2023-39203 | Alta (7.5) | 0.93% | — | 14 nov 2023 | Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access. |
| CVE-2023-39202 | Media (5.5) | 0.21% | — | 14 nov 2023 | Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access. |
| CVE-2023-39199 | Media (6.5) | 0.62% | — | 14 nov 2023 | Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access. |
| CVE-2023-39215 | Media (6.5) | 1.1% | — | 12 sept 2023 | Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
| CVE-2023-39213 | Crítica (9.8) | 1.4% | — | 8 ago 2023 | Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access. |
| CVE-2023-39218 | Media (4.9) | 1.1% | — | 8 ago 2023 | Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
| CVE-2023-36535 | Media (6.5) | 1.2% | — | 8 ago 2023 | Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access. |
| CVE-2023-36532 | Alta (7.5) | 1.5% | — | 8 ago 2023 | Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
| CVE-2023-34121 | Alta (8.8) | 0.95% | — | 13 jun 2023 | Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. |
| CVE-2023-34120 | Alta (7.8) | 0.13% | — | 13 jun 2023 | Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via local… |
| CVE-2023-28603 | Alta (7.1) | 0.16% | — | 13 jun 2023 | Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions. |
| CVE-2023-28597 | Alta (7.5) | 0.53% | — | 27 mar 2023 | Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker… |
| CVE-2023-22880 | Alta (7.5) | 0.98% | — | 16 mar 2023 | Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the… |
| CVE-2022-28763 | Crítica (9.6) | 1.2% | — | 31 oct 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct… |
| CVE-2022-28755 | Media (6.1) | 0.82% | — | 11 ago 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct… |
| CVE-2021-34424 | Alta (7.5) | 1.7% | — | 24 nov 2021 | A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom… |
| CVE-2021-34423 | Crítica (9.8) | 3.3% | — | 24 nov 2021 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version… |
Otros productos de Zoom
Rooms · 109Meeting Software Development KIT · 84Workplace Desktop · 75Zoom · 64Workplace Virtual Desktop Infrastructure · 60Rooms Controller · 44Workplace · 43Meetings · 37Video Software Development KIT · 23VDI Windows Meeting Clients · 9Zoom On-premise Meeting Connector MMR · 9Meeting Connector · 6