PT-2024-2724 · Zoom · Zoom Vdi Client For Windows+2

Shmoul

·

Published

2024-02-13

·

Updated

2024-10-04

·

CVE-2024-24695

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoom Desktop Client for Windows (affected versions not specified) Zoom VDI Client for Windows (affected versions not specified) Zoom Meeting SDK for Windows (affected versions not specified)
Description The issue is related to improper input validation, which may allow an authenticated user to disclose information via network access. This can be exploited by a remote attacker to reveal protected information.
Recommendations For Zoom Desktop Client for Windows, consider restricting network access until a fix is available. For Zoom VDI Client for Windows, avoid using the software for sensitive information exchange until the issue is resolved. For Zoom Meeting SDK for Windows, as a temporary workaround, consider disabling any functionality that relies on user input validation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02843
CVE-2024-24695

Affected Products

Zoom Desktop Client For Windows
Zoom Meeting Sdk For Windows
Zoom Vdi Client For Windows