CVE-2023-39203
CVE-2023-39203 is a medium-severity vulnerability in Zoom Virtual Desktop Infrastructure with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-789.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- EPSS exploit prediction: 1% (59th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-789
- Affected product: Zoom Virtual Desktop Infrastructure
- Published:
- Last modified:
Description
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
Frequently asked questions
- What is CVE-2023-39203?
- Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
- How severe is CVE-2023-39203?
- CVE-2023-39203 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2023-39203 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (59th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-39203?
- CVE-2023-39203 primarily affects Zoom Virtual Desktop Infrastructure. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-39203?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-39203 published?
- CVE-2023-39203 was published on 2023-11-14 and last updated on 2026-06-17.
References
Affected products (2)
- cpe:2.3:a:zoom:virtual_desktop_infrastructure:*:*:*:*:*:*:*:*
- cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
More vulnerabilities in Zoom Virtual Desktop Infrastructure
- CVE-2021-34423 — Critical (CVSS 9.8): A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and…
- CVE-2023-39213 — Critical (CVSS 9.6): Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may…
- CVE-2022-28755 — Critical (CVSS 9.6): The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a…
- CVE-2023-49647 — High (CVSS 8.8): Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows…
- CVE-2022-28763 — High (CVSS 8.8): The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a…
- CVE-2023-34120 — High (CVSS 8.7): Improper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before…
All CVEs affecting Zoom Virtual Desktop Infrastructure →
Other CWE-789 vulnerabilities
- CVE-2026-82435 — Critical (CVSS 9.8): Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the…
- CVE-2026-77410 — High (CVSS 8.9): RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the…
- CVE-2021-34869 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2021-34868 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2026-63574 — High (CVSS 8.7): Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers…
- CVE-2026-103603 — High (CVSS 8.7): Memory allocation with excessive size value in the HSS/LMS signature code (HssPublicKeyParameters, HssSignature) in…