CVE-2023-43582: Zoom Meetings

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

Affected products

  • Zoom Meetings: before 5.16.0 (fixed in 5.16.0)
  • Zoom Rooms: before 5.16.0 (fixed in 5.16.0)
  • Zoom Virtual Desktop Infrastructure: before 5.14.13 (fixed in 5.14.13); from 5.15.0, before 5.15.11 (fixed in 5.15.11)
  • Zoom Zoom: before 5.16.0 (fixed in 5.16.0)

Published 2023-11-15. Last modified 2026-06-17.