CVE Database
/

CVE-2023-28597

Back to search

CVE-2023-28597

Published: Mar 27, 2023

Modified: Feb 19, 2025

PUBLISHED

CVSS v3.1

8.3

HIGH

Description

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

VendorProductVersions

Zoom Video Communications Inc

Zoom (for Android, iOS, Linux, macOS, and Windows)

affected
unspecified - < 5.13.5

Zoom Video Communications Inc

Zoom Rooms (for Android, iOS, Linux, macOS, and Windows)

affected
unspecified - < 5.13.5

Zoom Video Communications Inc

Zoom VDI for Windows

affected
unspecified - < 5.13.10

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now