Количество 3
Количество 3

CVE-2023-28597
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.
GHSA-xwf7-9xfx-ghmm
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

BDU:2023-01785
Уязвимость программного обеспечения для проведения видеоконференций Zoom, связанная с нарушением доверительных границ при подключении к SMB-серверу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-28597 Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. | CVSS3: 8.3 | 1% Низкий | больше 2 лет назад |
GHSA-xwf7-9xfx-ghmm Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
![]() | BDU:2023-01785 Уязвимость программного обеспечения для проведения видеоконференций Zoom, связанная с нарушением доверительных границ при подключении к SMB-серверу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или выполнить произвольный код | CVSS3: 8.3 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу