VYPR

Zoom Desktop Client for Windows

by Zoom Video Communications, Inc.

CVEs (34)

  • CVE-2024-24694MedApr 9, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2023-39209MedAug 8, 2023
    risk 0.38cvss 5.9epss 0.01

    Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

  • CVE-2024-27247MedApr 9, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.

  • CVE-2023-39210MedAug 8, 2023
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Zoom Client SDK for Windows before 5.15.0 may allow an authenticated user to enable an information disclosure via local access.

  • CVE-2025-58135MedSep 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2024-24692MedMar 13, 2024
    risk 0.34cvss 5.3epss 0.00

    Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

  • CVE-2025-58134MedSep 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.

  • CVE-2023-39203MedNov 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

  • CVE-2023-28599MedJun 13, 2023
    risk 0.28cvss 4.3epss 0.01

    Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.

  • CVE-2025-58132MedOct 15, 2025
    risk 0.27cvss 4.1epss 0.02

    Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2024-27242MedApr 9, 2024
    risk 0.27cvss 4.1epss 0.00

    Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct a denial of service via network access.

  • CVE-2023-34121MedJun 13, 2023
    risk 0.27cvss 4.1epss 0.01

    Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.

  • CVE-2023-39202LowNov 14, 2023
    risk 0.20cvss 3.1epss 0.00

    Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

  • CVE-2023-28602LowJun 13, 2023
    risk 0.18cvss 2.8epss 0.00

    Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

Page 2 of 2