Buffer overflow in Zoom Video Communications, Inc. products - CVE-2024-27243

 

Buffer overflow in Zoom Video Communications, Inc. products - CVE-2024-27243

Published: March 17, 2025


Vulnerability identifier: #VU105749
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-27243
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Zoom Video Communications, Inc.
Affected software:
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Virtual Desktop Infrastructure (VDI)
Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Meeting SDK for Windows
Zoom Meeting SDK for iOS
Zoom Meeting SDK for Android
Zoom Meeting SDK for macOS
Zoom Meeting SDK for Linux

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in some Zoom Workplace Apps and SDKs. A remote attacker can trick the victim into performing certain actions and crash the application.


How to mitigate CVE-2024-27243

Install updates from vendor's website.

Sources