CRITICAL🇵🇱 Wersja polska

CVE-2024-24691

CVSS 9.6v3.1pub. 2024-02-14upd. 2024-11-21

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

🤖 AI Analysis
How it works

The vulnerability consists of improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. An attacker can send specially crafted data over the network to the vulnerable application without needing any authentication. User interaction is required (UI:R), meaning the victim must perform a specific action, such as opening a malicious link or joining a crafted meeting. This results in privilege escalation in the context of the attacked system.

Impact

An unauthenticated attacker can obtain elevated privileges on the victim's system, potentially leading to system takeover, breach of data confidentiality and integrity, and disruption of service availability.

Mitigation & patch

Apply patches available from the vendor according to references — detailed information about patched versions is available in Zoom's security bulletin: https://www.zoom.com/en/trust/security-bulletin/ZSB-24008/

Who is affected

Zoom Desktop Client for Windows, Zoom VDI Client for Windows, Zoom Meeting SDK for Windows, Zoom Rooms — versions indicated in vendor references (bulletin ZSB-24008)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Zoom Meeting Software Development Kit

    APP
    Zoom
    < 5.16.5
  • Zoom Rooms

    APP
    Zoom
    < 5.17.0
  • Zoom Vdi Windows Meeting Clients

    APP
    Zoom
    < 5.14.14< 5.15.12< 5.16.10
  • Zoom

    APP
    Zoom
    < 5.16.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-49457CRITICAL9.6PL ✓same product

Untrusted search path w klientach Zoom dla Windows — privilege escalation przez sieć

CVE-2023-39213CRITICAL9.6PL ✓same product

Zoom Desktop Client i VDI Client — privilege escalation przez sieć

CVE-2023-39216CRITICAL9.6PL ✓same product

Nieprawidłowa walidacja danych wejściowych w Zoom Desktop Client dla Windows — privilege escalation

CVE-2023-36534CRITICAL9.3PL ✓same product

Path traversal w Zoom Desktop Client dla Windows — eskalacja uprawnień

CVE-2022-28755CRITICAL9.6PL ✓same product

Zoom Client — podatność parsowania URL umożliwiająca RCE