← Vulnerability feed

Vulnerability record · CVE-2023-22883 · published 16 March 2023

CVE-2023-22883: Zoom meetings toctou race condition vulnerability

Zoom · Meetings

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.

7.8 CVSS 3.1 High EPSS 0.19% · top 92.8% CWE-367 · TOCTOU race condition
7.8CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to the SYSTEM user.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22883 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-34423Zoom meetings classic buffer overflow vulnerabilityA buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom C…EPSS 3.3%9.8CVE-2021-33907Zoom meetings improper certificate validation vulnerabilityThe Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files …EPSS 3.0%9.6CVE-2022-28763Zoom meetings improper input validation vulnerabilityThe Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a …EPSS 1.2%9.1CVE-2022-22785Zoom meetings reliance on cookies without validation vulnerabilityThe Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies …EPSS 3.5%8.8CVE-2023-43582Zoom meetings improper authentication vulnerabilityImproper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.EPSS 0.66%8.8CVE-2022-22786Zoom meetings download of code without integrity check vulnerabilityThe Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properl…EPSS 1.5%8.1CVE-2022-22784Zoom meetings xml injection vulnerabilityThe Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP message…EPSS 4.0%7.8CVE-2023-28596Zoom meetings uncontrolled search path element vulnerabilityZoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2023-22883), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.