CVE-2023-34118
📛 CVE Title
CVE-2023-34118
Description
Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Zoom
- CVSS severity
- HIGH
- CVSS score
- 7.3 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L- Effective score
- 7.3 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-250 - Reserved
- 2023-05-26
- Published
- 2023-07-11 19:01 UTC
- Last updated
- 2024-10-22 22:34 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/34xxx/CVE-2023-34118.json
- Linked Threat
- CVE-2023-34118 — CVE-2023-34118
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-38220 - Assigner
- Zoom
- Published
- Jul 11, 2023, 5:01:56 PM
- Updated
- Oct 22, 2024, 8:34:26 PM
- EUVD base score (CVSS 3.1)
-
7.3 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L - EUVD-reported EPSS
- 0.0400
- Vendors
- Zoom Video Communications, Inc.
- Products
-
Zoom Rooms for Windows (before 5.14.5)
- Aliases
-
GHSA-w79p-2q4q-mwmw
ENISA description: Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Zoom Video Communications, Inc. | Zoom Rooms for Windows |
before 5.14.5 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (15)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:helpx.adobe.com
This page contains important information regarding security vulnerabilities that could affect specific versions of Adobe products. Use this information to take the prescribed corrective actions.
2026-06-15 20:11 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-06-15 20:11 UTC -
web:www.hipaajournal.com
CISA's solution is to patch smarter, not harder. CISA has released a new risk-based vulnerability remediation framework to help vendors assess vulnerabilities and prioritize patching effectively, concentrating their efforts on mitigating vulnerabilities in the most at-risk assets and addressing vulnerabilities that carry the greatest risk of ...
2026-06-15 20:11 UTC -
web:www.cisa.gov
Organizations should consider additional attack vectors and mitigation strategies based on their unique environment. Contact To schedule a Risk and Vulnerability Assessment, contact central@cisa.dhs.gov .
2026-06-15 20:11 UTC -
web:github.com
CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes
2026-06-15 20:11 UTC -
web:support.servicenow.com
This document lists all the released Store applications and schema changes for Vulnerability Response and Configuration Compliance. Vulnerability Response and Configuration Compliance Compatibility Matrix
2026-05-22 06:39 UTC -
web:www.cisa.gov
If vulnerabilities cannot be remediated within the recommended timeframes, develop a remediation plan for action and coordination across the organization. The remediation plan should include: Vulnerability remediation constraints Interim mitigation actions to overcome constraints Final actions required to remediate vulnerability
2026-05-22 06:39 UTC -
web:www.cisco.com
This document describes a list of software versions that have incorporated fixes for Cisco IOS® XE Software Web UI Cisco bug ID CSCwh87343.
2026-05-22 06:39 UTC -
web:www.manageengine.com
Patch Details: The name of the patch and the affected products. Patch Details The following patch details are shown: Patch ID: A unique reference ID for every patch Patch Name: The name of the patch Bulletin ID: The Bulletin ID pertaining to this patch MS Knowledge Base: The knowledge base article corresponding to this patch .
2026-05-22 06:39 UTC -
web:cybersecuritynews.com
Google released a critical Chrome update fixing multiple high-risk vulnerabilities that could enable arbitrary code execution.
2026-05-22 06:39 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-22 06:39 UTC -
web:github.com
A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.
2026-05-22 06:39 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 06:39 UTC -
web:source.android.com
This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.
2026-05-22 06:39 UTC -
web:support.esri.com
Refer to the Issues Addressed with this Patch section for details about BUG-000171492. The new patch when shown as available in the ArcGIS Enterprise Patch Notification tool, is listed as ArcGIS Server Security 2025 Update 1 Patch with a release date of April 17, 2025; once installed, it is listed as ArcGIS Server Security 2025 Update 1 Patch B.
2026-05-22 06:39 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-34118.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T16:01:54.132Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://explore.zoom.us/en/trust/security/security-bulletin/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-34118",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-22T20:30:52.521794Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-10-22T20:34:26.157Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Zoom Rooms for Windows",
"vendor": "Zoom Video Communications, Inc.",
"versions": [
{
"status": "affected",
"version": "before 5.14.5"
}
]
}
],
"datePublic": "2023-07-11T12:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.<br>"
}
],
"value": "Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-250",
"description": "CWE-250: Execution with Unnecessary Privileges",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-09-19T19:29:43.915Z",
"orgId": "99b9af0d-a833-4a5d-9e2f-8b1324f35351",
"shortName": "Zoom"
},
"references": [
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin/"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "99b9af0d-a833-4a5d-9e2f-8b1324f35351",
"assignerShortName": "Zoom",
"cveId": "CVE-2023-34118",
"datePublished": "2023-07-11T17:01:56.053Z",
"dateReserved": "2023-05-25T22:01:29.097Z",
"dateUpdated": "2024-10-22T20:34:26.157Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}