Unauthenticated Escalation of Privilege Vulnerability in Zoom Desktop Client for Windows

CVE-2024-24691
9.8CRITICAL

Key Information

Status
Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows
Vendor
CVE Published:
14 February 2024

Badges

🔥 No. 1 Trending😄 Trended📰 News Worthy

Summary

A critical flaw, identified as CVE-2024-24691, was discovered in Zoom's desktop and mobile applications, particularly affecting Windows software. This vulnerability, along with six others, was addressed by Zoom. The CVE-2024-24691 vulnerability is associated with an improper input validation bug, and an escalation of privilege can be achieved by an attacker with network access. Other vulnerabilities, such as CVE-2024-24697, also allow for an escalation of privilege, and these issues can pose a significant security risk. Users are advised to promptly update their applications to the latest available versions to mitigate these vulnerabilities. No known exploitation of these vulnerabilities has been reported, and the company is working to ensure the security of its applications.

Affected Version(s)

Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows = see references

News Articles

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • From: null to: 9.6

  • 🔥

    Vulnerability reached the number 1 worldwide trending spot.

  • Vulnerability started trending.

  • Vulnerability published.

  • First article discovered by securityonline.info

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database4 News Article(s)
.