[High Risk] Privilege Escalation Vulnerability in Zoom Desktop Client for Windows <5.14.5

Vulnerability description

Zoom is a software platform for video conferencing, online meetings and remote collaboration.

Versions of Zoom Desktop Client for Windows prior to 5.14.5 have insufficient data authenticity verification, allowing an authenticated attacker to escalate privileges to the SYSTEM user through network access.

Vulnerability name Zoom Desktop Client for Windows <5.14.5 Privilege Escalation Vulnerability
Vulnerability type Permissions, Privileges, and Access Control
Discovery time 2023/8/9
Vulnerability Breadth generally
MPS number MPS-4nof-le32
CVE number CVE-2023-36541
CNVD number -

Sphere of influence

Zoom Desktop Client for Windows@(-∞, 5.14.5)

Repair plan

Upgrade Zoom Desktop Client for Windows to version 5.14.5 or later

The official patch has been released: https://zoom.us/download

reference link

https://www.oscs1024.com/hd/MPS-4nof-le32

https://nvd.nist.gov/vuln/detail/CVE-2023-36541

https://explore.zoom.us/en/trust/security/security-bulletin/

https://zoom.us/download

About Murphy Security

Murphy Security is a technology company that provides you with professional software supply chain security management. The core team comes from Baidu, Huawei, Wuyun and other enterprises. The company provides customers with a complete software supply chain security management platform, and provides software with a full life cycle around SBOM Security management, platform capabilities include software component analysis, source security management, container image detection, vulnerability intelligence early warning and commercial software supply chain access assessment and other products. Provide customers with complete control capabilities from supply chain asset identification management, risk detection, security control, and one-key repair.
Open source project: https://github.com/murphysecurity/murphysec/?sf=qbyj

The product can be integrated with various tools in the existing development process at a very low cost, including seamless integration with dozens of tools such as IDE, Gitlab, Bitbucket, Jenkins, Harbor, and Nexus.
Free code security detection tool: https://www.murphysec.com/?sf=qbyj
Free intelligence subscription: https://www.oscs1024.com/cm/?sf=qbyj

insert image description here

Guess you like

Origin blog.csdn.net/murphysec/article/details/132204929