📦

meetings

Vendor: zoom

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 3 Remote Access
Total CVEs 42 Total Indexed
Avg. EPSS 1.11% Exploit Prob.
Latest CVE CVE-2023-43588 Nov 15

Security Vulnerability Index

Page 1 / 5
3.5 CVSS

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

EPSS: 0.65%
5.5 CVSS

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

EPSS: 0.66%
3.7 CVSS

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

EPSS: 1.14%
4.3 CVSS

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

EPSS: 0.86%
4.3 CVSS

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

EPSS: 1.06%
4.9 CVSS

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

EPSS: 0.62%
5.3 CVSS

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

EPSS: 0.53%
7.8 CVSS

Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to privileges to root.

EPSS: 0.26%
7.2 CVSS

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.

EPSS: 0.19%
8.8 CVSS

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

EPSS: 0.18%