Vulnerability · NVD
CVE-2023-49647
HIGH 8.8
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
Attack vector : Local
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
0.25%
exploit very unlikely
percentile 16.0%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
NVD references 5 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| zoom |
zoom Windows
|
Windows | <5.16.10 | cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:* |