Zoom Client是美国Zoom公司的一款支持多种平台的视频会议客户端应用程序。 Zoom Client 5.13.10之前版本存在安全漏洞,该漏洞源于包含一个 HTML 注入,攻击者利用该漏洞可以将 HTML 注入到显示名称中,从而可能在会议创建期间将受害者引导至恶意网站。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Video Communications, Inc. | Zoom for Android | before 5.13.10 | - |
|
| Zoom Video Communications, Inc. | Zoom for iOS | before 5.13.10 | - |
|
| Zoom Video Communications, Inc. | Zoom for Linux | before 5.13.10 | - |
|
| Zoom Video Communications, Inc. | Zoom for macOS | before 5.13.10 | - |
|
| Zoom Video Communications, Inc. | Zoom for Windows | before 5.13.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-34120 | 8.7 HIGH | Zoom Rooms 安全漏洞 |
| CVE-2023-28601 | 8.3 HIGH | Zoom Client 缓冲区错误漏洞 |
| CVE-2023-28603 | 7.7 HIGH | Zoom VDI client installer 安全漏洞 |
| CVE-2023-28598 | 7.5 HIGH | Zoom Client 注入漏洞 |
| CVE-2023-34114 | 7.4 HIGH | Zoom Client 安全漏洞 |
| CVE-2023-28600 | 5.2 MEDIUM | Zoom Client 安全漏洞 |
| CVE-2023-34115 | 4.3 MEDIUM | Zoom Meeting SDK 安全漏洞 |
| CVE-2023-34121 | 4.1 MEDIUM | Zoom Rooms 安全漏洞 |
| CVE-2023-28602 | 2.8 LOW | Zoom Client 数据伪造问题漏洞 |
No comments yet