CVE-2023-22880
Information Disclosure in Zoom for Windows Clients
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsoft’s telemetry behavior.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-01-09 CVE Reserved
- 2023-03-16 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://explore.zoom.us/en/trust/security/security-bulletin | 2023-03-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zoom Search vendor "Zoom" | Rooms Search vendor "Zoom" for product "Rooms" | < 5.13.3 Search vendor "Zoom" for product "Rooms" and version " < 5.13.3" | windows |
Affected
| ||||||
Zoom Search vendor "Zoom" | Virtual Desktop Infrastructure Search vendor "Zoom" for product "Virtual Desktop Infrastructure" | < 5.13.1 Search vendor "Zoom" for product "Virtual Desktop Infrastructure" and version " < 5.13.1" | windows |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom Search vendor "Zoom" for product "Zoom" | < 5.13.3 Search vendor "Zoom" for product "Zoom" and version " < 5.13.3" | windows |
Affected
|