📦 Virtual Desktop Infrastructure

by Zoom

🔍 What is Virtual Desktop Infrastructure?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-39213

CRITICAL CVSS 9.6 Aug 8, 2023

This vulnerability in Zoom Desktop Client for Windows and Zoom VDI Client allows an unauthenticated attacker to escalate privileges via network access by exploiting improper neutralization of special ...

CVE-2023-49647

HIGH CVSS 8.8 Jan 12, 2024

This vulnerability allows authenticated users on Windows systems to escalate their privileges through local access to the Zoom Desktop Client, Zoom VDI Client, or Zoom SDKs. Attackers could gain highe...

CVE-2023-39215

HIGH CVSS 7.1 Sep 12, 2023

This vulnerability in Zoom clients allows authenticated users to cause denial of service attacks through network access. It affects Zoom users who have authentication credentials and could disrupt mee...

CVE-2023-28603

HIGH CVSS 7.7 Jun 13, 2023

The Zoom VDI client installer prior to version 5.14.0 contains an improper access control vulnerability that allows a malicious user to delete local files without proper permissions. This affects orga...

CVE-2023-34120

HIGH CVSS 8.7 Jun 13, 2023

This vulnerability allows authenticated users on Windows systems to escalate privileges by leveraging Zoom client's elevated system permissions to spawn processes with higher privileges. It affects Zo...

CVE-2023-28597

HIGH CVSS 8.3 Mar 27, 2023

Zoom clients before version 5.13.5 have a vulnerability where saving recordings to SMB locations and opening them via Zoom's web portal can allow adjacent network attackers to intercept requests with ...

CVE-2021-34424

HIGH CVSS 7.5 Nov 24, 2021

This vulnerability in Zoom clients and servers allows attackers to read arbitrary memory contents, potentially exposing sensitive information like session tokens, passwords, or encryption keys. It aff...