Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of information via network access.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NZoom
APPZoom< 6.4.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2024-24691CRITICAL9.6PL ✓same product
Privilege escalation w Zoom Desktop Client, VDI Client i Meeting SDK dla Windows
CVE-2023-39213CRITICAL9.6PL ✓same product
Zoom Desktop Client i VDI Client — privilege escalation przez sieć
CVE-2023-39216CRITICAL9.6PL ✓same product
Nieprawidłowa walidacja danych wejściowych w Zoom Desktop Client dla Windows — privilege escalation
CVE-2023-36534CRITICAL9.3PL ✓same product
Path traversal w Zoom Desktop Client dla Windows — eskalacja uprawnień
CVE-2022-28755CRITICAL9.6PL ✓same product
Zoom Client — podatność parsowania URL umożliwiająca RCE