PT-2024-5135 · Zoom · Zoom

Published

2024-07-09

·

Updated

2025-08-05

·

CVE-2024-27238

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Zoom versions prior to 6.0.0
Description: The issue is related to a race condition error in the installer for some Zoom Apps and SDKs for Windows, which may allow an authenticated user to conduct a privilege escalation via local access. This is also described as a "ситуация гонки" or situation where synchronization errors occur when using a shared resource.
Recommendations: For versions prior to 6.0.0, update to version 6.0.0 or later to resolve the issue. As a temporary workaround, consider restricting local access to the installer for Zoom Apps and SDKs to minimize the risk of exploitation.

Fix

LPE

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2024-05682
CVE-2024-27238

Affected Products

Zoom