PT-2024-2687 · Zoom · Zoom Vdi Client For Windows+2

Shmoul

·

Published

2024-02-13

·

Updated

2024-10-04

·

CVE-2024-24696

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoom Desktop Client for Windows (affected versions not specified) Zoom VDI Client for Windows (affected versions not specified) Zoom Meeting SDK for Windows (affected versions not specified)
Description The issue is related to improper input validation in Zoom software for Windows, which may allow an authenticated user to disclose information via network access. This can be exploited by a remote attacker to reveal protected information.
Recommendations For Zoom Desktop Client for Windows, consider restricting network access until a fix is available. For Zoom VDI Client for Windows, avoid using the software for sensitive information exchange until the issue is resolved. For Zoom Meeting SDK for Windows, as a temporary workaround, consider disabling the chat functionality to minimize the risk of information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02797
CVE-2024-24696

Affected Products

Zoom Desktop Client For Windows
Zoom Meeting Sdk For Windows
Zoom Vdi Client For Windows