CVE-2023-28603: Zoom Virtual Desktop Infrastructure

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.

Affected products

  • Zoom Virtual Desktop Infrastructure: before 5.14.0 (fixed in 5.14.0)

Published 2023-06-13. Last modified 2026-06-17.