Input validation error in Zoom Video Communications, Inc. products - CVE-2024-24691

 

Input validation error in Zoom Video Communications, Inc. products - CVE-2024-24691

Published: February 14, 2024


Vulnerability identifier: #VU86517
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-24691
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to click on a specially crafted link and execute arbitrary code on the system.


Affected software

Zoom Rooms Client for Windows
Zoom Workplace Desktop App for Windows
Virtual Desktop Infrastructure (VDI)
Zoom Meeting SDK for Windows

How to mitigate CVE-2024-24691

Install updates from vendor's website.

Zoom Rooms Client for Windows - update to 5.17.0 3530
Zoom Workplace Desktop App for Windows - update to 5.16.5 24296
Virtual Desktop Infrastructure (VDI) - update to 5.16.10 24420
Zoom Meeting SDK for Windows - update to 5.16.5

External References

Related Security Bulletins