Tracker / CVE-2023-28597
CVE-2023-28597
High 8.3
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.
Affected products and versions
| zoom | rooms · … → 5.13.5 |
|---|---|
| zoom | virtual_desktop_infrastructure · … → 5.13.10 |
| zoom | zoom · … → 5.13.5 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.