s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-34118

📛 CVE Title

CVE-2023-34118

Description

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

Overview

State
PUBLISHED
Assigner (CNA)
Zoom
CVSS severity
HIGH
CVSS score
CVSS 7.3 / 10 7.3 7.3 / 10
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Effective score
7.3 / 10 HIGH source: CNA overview
CWE(s)
CWE-250
Reserved
2023-05-26
Published
2023-07-11 19:01 UTC
Last updated
2024-10-22 22:34 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/34xxx/CVE-2023-34118.json
Linked Threat
CVE-2023-34118 — CVE-2023-34118

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-38220
Assigner
Zoom
Published
Jul 11, 2023, 5:01:56 PM
Updated
Oct 22, 2024, 8:34:26 PM
EUVD base score (CVSS 3.1)
7.3 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
EUVD-reported EPSS
0.0400
Vendors
Zoom Video Communications, Inc.
Products
Zoom Rooms for Windows (before 5.14.5)
Aliases
GHSA-w79p-2q4q-mwmw

ENISA description: Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
Zoom Video Communications, Inc. Zoom Rooms for Windows before 5.14.5 (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (15)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:helpx.adobe.com

    This page contains important information regarding security vulnerabilities that could affect specific versions of Adobe products. Use this information to take the prescribed corrective actions.

    2026-06-15 20:11 UTC
  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

    2026-06-15 20:11 UTC
  • web:www.hipaajournal.com

    CISA's solution is to patch smarter, not harder. CISA has released a new risk-based vulnerability remediation framework to help vendors assess vulnerabilities and prioritize patching effectively, concentrating their efforts on mitigating vulnerabilities in the most at-risk assets and addressing vulnerabilities that carry the greatest risk of ...

    2026-06-15 20:11 UTC
  • web:www.cisa.gov

    Organizations should consider additional attack vectors and mitigation strategies based on their unique environment. Contact To schedule a Risk and Vulnerability Assessment, contact central@cisa.dhs.gov .

    2026-06-15 20:11 UTC
  • web:github.com

    CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes

    2026-06-15 20:11 UTC
  • web:support.servicenow.com

    This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix

    2026-05-22 06:39 UTC
  • web:www.cisa.gov

    If vulnerabilities cannot be remediated within the recommended timeframes, develop a remediation plan for action and coordination across the organization. The remediation plan should include: Vulnerability remediation constraints Interim mitigation actions to overcome constraints Final actions required to remediate vulnerability

    2026-05-22 06:39 UTC
  • web:www.cisco.com

    This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.

    2026-05-22 06:39 UTC
  • web:www.manageengine.com

    Patch Details: The name of the patch and the affected products. Patch Details The following patch details are shown: Patch ID: A unique reference ID for every patch Patch Name: The name of the patch Bulletin ID: The Bulletin ID pertaining to this patch MS Knowledge Base: The knowledge base article corresponding to this patch .

    2026-05-22 06:39 UTC
  • web:cybersecuritynews.com

    Google released a critical Chrome update fixing multiple high-risk vulnerabilities that could enable arbitrary code execution.

    2026-05-22 06:39 UTC
  • web:www.oracle.com

    Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

    2026-05-22 06:39 UTC
  • web:github.com

    A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.

    2026-05-22 06:39 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 06:39 UTC
  • web:source.android.com

    This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.

    2026-05-22 06:39 UTC
  • web:support.esri.com

    Refer to the Issues Addressed with this Patch section for details about BUG-000171492. The new patch when shown as available in the ArcGIS Enterprise Patch Notification tool, is listed as ArcGIS Server Security 2025 Update 1 Patch with a release date of April 17, 2025; once installed, it is listed as ArcGIS Server Security 2025 Update 1 Patch B.

    2026-05-22 06:39 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2023-34118.json.

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T16:01:54.132Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://explore.zoom.us/en/trust/security/security-bulletin/"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-34118",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-22T20:30:52.521794Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-22T20:34:26.157Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Zoom Rooms for Windows",
          "vendor": "Zoom Video Communications, Inc.",
          "versions": [
            {
              "status": "affected",
              "version": "before 5.14.5"
            }
          ]
        }
      ],
      "datePublic": "2023-07-11T12:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.<br>"
            }
          ],
          "value": "Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-250",
              "description": "CWE-250: Execution with Unnecessary Privileges",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-09-19T19:29:43.915Z",
        "orgId": "99b9af0d-a833-4a5d-9e2f-8b1324f35351",
        "shortName": "Zoom"
      },
      "references": [
        {
          "url": "https://explore.zoom.us/en/trust/security/security-bulletin/"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 0.1.0-dev"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "99b9af0d-a833-4a5d-9e2f-8b1324f35351",
    "assignerShortName": "Zoom",
    "cveId": "CVE-2023-34118",
    "datePublished": "2023-07-11T17:01:56.053Z",
    "dateReserved": "2023-05-25T22:01:29.097Z",
    "dateUpdated": "2024-10-22T20:34:26.157Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}