Potential Escalation of Privilege via Local Access in Zoom Installer
CVE-2024-24694

5.9MEDIUM

Key Information:

Vendor
Zoom
Vendor
CVE Published:
9 April 2024

Summary

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via local access.

Affected Version(s)

Zoom Desktop Client for Windows Windows before version 5.17.10

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.