CyberzSOC

Publication detail
← Back to advisories & guidance

2024-020: Critical Vulnerability in Zoom Products ↗ source

February 15, 2024 CERT-EU Advisory

Summary

If exploited, this vulnerability allows an unauthenticated attacker to conduct privilege escalation on the target system via network access. The vulnerability CVE-2024-24691 , with a CVSS score of 9.6, is due to an improper input validation flaw that could allow an unauthenticated attacker to conduct privilege escalation on the target system over the network. This vulnerability impacts the following products: It is recommended applying updates as soon as possible [2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-24691 9.6 Critical Zoom Video Communications, Inc. Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.