Loading HuntDB...

GHSA-xwf7-9xfx-ghmm

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

Related CVEs

Key Information

GHSA ID
GHSA-xwf7-9xfx-ghmm
Published
July 6, 2023 7:24 PM
Last Modified
February 19, 2025 6:32 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.