Input validation error in Zoom Video Communications, Inc. products - CVE-2024-24691
Published: February 14, 2024
Vulnerability identifier: #VU86517
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24691
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to click on a specially crafted link and execute arbitrary code on the system.
Affected software
Zoom Rooms Client for Windows
Zoom Workplace Desktop App for Windows
Virtual Desktop Infrastructure (VDI)
Zoom Meeting SDK for Windows
Zoom Workplace Desktop App for Windows
Virtual Desktop Infrastructure (VDI)
Zoom Meeting SDK for Windows
How to mitigate CVE-2024-24691
Install updates from vendor's website.
Zoom Rooms Client for Windows - update to 5.17.0 3530
Zoom Workplace Desktop App for Windows - update to 5.16.5 24296
Virtual Desktop Infrastructure (VDI) - update to 5.16.10 24420
Zoom Meeting SDK for Windows - update to 5.16.5
Zoom Workplace Desktop App for Windows - update to 5.16.5 24296
Virtual Desktop Infrastructure (VDI) - update to 5.16.10 24420
Zoom Meeting SDK for Windows - update to 5.16.5