Information Disclosure Vulnerability in Zoom Workplace Apps
CVE-2024-45426

4.9MEDIUM

Key Information:

Vendor
Zoom Communications, Inc
Status
Zoom Workplace Apps
Vendor
CVE Published:
25 February 2025

Summary

An incorrect ownership assignment in certain versions of Zoom Workplace Apps allows a privileged user to potentially disclose sensitive information via network access. This vulnerability highlights the importance of proper access control and ownership assignment to protect user data from unintended exposure.

Affected Version(s)

Zoom Workplace Apps Windows See references

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.