CVE-2023-34115

Published Jun 13, 2023

Last updated a year ago

Overview

Description
Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.
Source
security@zoom.us
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
3.8
Impact score
1.4
Exploitability score
2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Severity
LOW

Weaknesses

nvd@nist.gov
CWE-120
security@zoom.us
CWE-120

Social media

Hype score
Not currently trending

Configurations