AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-22880

MEDIUM · CVSS 6.8 EPSS 0.98%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-03-16 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. It affects Microsoft, Windows.

CVE
CVE-2023-22880
Severity
MEDIUM
CVSS
6.8
EPSS
0.98%
Microsoft Windows

Original NVD Description

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsoft’s telemetry behavior.

Related CVEs

Other vulnerabilities affecting the same vendor(s)