CVE-2023-28601: Zoom

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client.

Affected products

  • Zoom Zoom: before 5.14.0 (fixed in 5.14.0)

Published 2023-06-13. Last modified 2026-06-17.