CVE-2023-39218: Zoom Rooms

Medium severity, CVSS 4.9. EPSS: 1.1% chance of exploitation in the next 30 days.

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

Affected products

  • Zoom Rooms: before 5.14.10 (fixed in 5.14.10)
  • Zoom Virtual Desktop Infrastructure: before 5.14.10 (fixed in 5.14.10)
  • Zoom Zoom: before 5.14.10 (fixed in 5.14.10)

Published 2023-08-08. Last modified 2026-06-17.