PT-2024-5135 · Zoom · Zoom
Published
2024-07-09
·
Updated
2025-08-05
·
CVE-2024-27238
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Zoom versions prior to 6.0.0
Description:
The issue is related to a race condition error in the installer for some Zoom Apps and SDKs for Windows, which may allow an authenticated user to conduct a privilege escalation via local access. This is also described as a "ситуация гонки" or situation where synchronization errors occur when using a shared resource.
Recommendations:
For versions prior to 6.0.0, update to version 6.0.0 or later to resolve the issue. As a temporary workaround, consider restricting local access to the installer for Zoom Apps and SDKs to minimize the risk of exploitation.
Fix
LPE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoom