CVE-2023-39202: Zoom Rooms

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Untrusted search path in Zoom Rooms Client for Windows and Zoom VDI Client may allow a privileged user to conduct a denial of service via local access.

Affected products

  • Zoom Rooms: before 5.16.0 (fixed in 5.16.0)
  • Zoom Virtual Desktop Infrastructure: before 5.14.13 (fixed in 5.14.13); from 5.15.0, before 5.15.11 (fixed in 5.15.11)

Published 2023-11-14. Last modified 2026-06-17.