Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.
📦
meeting_software_development_kit
Vendor: zoom
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
5
Remote Access
Total CVEs
134
Total Indexed
Avg. EPSS
0.44%
Exploit Prob.
Security Vulnerability Index
Page 9 / 14
7.6
CVSS
Severity: HIGH
5.5
CVSS
Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.
Severity: MEDIUM
5.3
CVSS
Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.
Severity: MEDIUM
7.1
CVSS
CVE-2023-36533
RCE
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
Severity: HIGH