Описание
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.3.14 (исключая)Версия от 6.4.0 (включая) до 6.4.14 (исключая)Версия от 6.5.0 (включая) до 6.5.10 (исключая)
Одно из
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:macos:*:*
EPSS
Процентиль: 4%
0.00018
Низкий
6.6 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-646
Связанные уязвимости
CVSS3: 6.6
github
3 месяца назад
Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.4.14, and 6.5.10 in their respective tracks may allow an authenticated user to conduct a disclosure of information via network access.
EPSS
Процентиль: 4%
0.00018
Низкий
6.6 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-646