Virtual Desktop Infrastructure
Vendor:
First CVE: Nov 24, 2021 · Active for 4 years
25
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Virtual Desktop Infrastructure over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2021
4 years ago
Most Recent CVE
Jan 12, 2024
925 days ago
CVE Severity & Scoring
Virtual Desktop Infrastructure25 CVEs
36%
52%
12%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (16.0%)
Network20 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None22 (88.0%)
Unknown0 (0.0%)
Required3 (12.0%)
Privileges Required
Low12 (48.0%)
High1 (4.0%)
None12 (48.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34423CRITICAL A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackber | Nov 24, 2021 | 9.8 | 34 | NO | NO |
CVE-2023-43586HIGH Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via | Dec 13, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-39213CRITICAL Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privil | Aug 8, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-34121HIGH Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation | Jun 13, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-34424HIGH A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Andr | Nov 24, 2021 | 7.5 | 25 | NO | NO |
CVE-2023-43582HIGH Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. | Nov 15, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-22880HIGH Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosur | Mar 16, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-36532HIGH Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. | Aug 8, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-28597HIGH Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link | Mar 27, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-28763CRITICAL The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is o | Oct 31, 2022 | 9.6 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Virtual Desktop Infrastructure
Top CWEs
Versions
No cataloged versions.