PT-2024-5134 · Zoom · Zoom Sdks For Windows+1

Shmoul

·

Published

2024-07-09

·

Updated

2025-10-02

·

CVE-2024-39826

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Zoom Workplace Apps and SDKs for Windows (affected versions not specified)
Description: The issue is related to path traversal in Team Chat, which may allow an authenticated user to disclose information via network access. It is also associated with synchronization errors, specifically a "race condition" when using a shared resource, potentially enabling a remote attacker to reveal protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2024-05681
CVE-2024-39826

Affected Products

Zoom Sdks For Windows
Zoom Workplace Apps