Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2023-36539

MEDIUM 5.3

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

Attack vector : Network No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS 0.53% exploit very unlikely percentile 42.1%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Zoom macOS us.zoom.xos
    Affected Fixed in Latest tracked undetermined
  • Zoom Android us.zoom.videomeetings
    Affected Fixed in Latest tracked 5.10.4.5757 undetermined
  • Zoom Workplace Windows winget:Zoom.Zoom
    Affected Fixed in Latest tracked 7.1.43453 undetermined
  • Zoom iOS ios:us.zoom.videomeetings
    Affected Fixed in Latest tracked 7.1.5 undetermined

NVD references 14 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗

Vulnerable CPE configurations (7)
Vendor Product Versions
zoom meetings
Android
zoom meetings
iOS
zoom zoom
Android
zoom zoom
iOS
zoom zoom
macOS
zoom zoom
Windows
zoom zoom
Windows
View on NVD ↗ Advisory · explore.zoom.us