Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://www.zoom.com/en/trust/security-bulletin/ZSB-23062/ | vendor advisory |