Buffer overflow in Zoom Video Communications, Inc. products - CVE-2024-27245

 

Buffer overflow in Zoom Video Communications, Inc. products - CVE-2024-27245

Published: June 11, 2024


Vulnerability identifier: #VU91690
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27245
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A remote attacker can pass specially crafted data to the application, trigger memory corruption and perform a denial of service 9DoS) attack.


Affected software

Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Rooms Client for iPad
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Rooms Client for macOS
Zoom Rooms Client for Windows
Zoom Meeting SDK for Windows
Zoom Meeting SDK for macOS
Zoom Meeting SDK for iOS
Zoom Meeting SDK for Android
Zoom Meeting SDK for Linux
Virtual Desktop Infrastructure (VDI)

How to mitigate CVE-2024-27245

Install updates from vendor's website.

Zoom Workplace App for iOS - update to 5.17.11 14172
Zoom Workplace Desktop App for Windows - update to 5.17.11 34827
Zoom Workplace Desktop App for macOS - update to 5.17.11 31580
Zoom Workplace App for Android - update to 5.17.11 20383
Zoom Workplace Desktop App for Linux - update to 5.17.11 3835
Zoom Rooms Client for macOS - update to 6.0.0 6108
Zoom Rooms Client for Windows - update to 6.0.0
Zoom Meeting SDK for Windows - update to 5.17.11
Zoom Meeting SDK for macOS - update to 5.17.11
Zoom Meeting SDK for iOS - update to 5.17.11
Zoom Meeting SDK for Android - update to 5.17.11
Virtual Desktop Infrastructure (VDI) - addressed in versions 5.15.17.24820, 5.16.15.24830, 5.17.11 24850
Zoom Meeting SDK for Linux - update to 5.17.11
Zoom Rooms Client for iPad - update to 6.0.0

External References

Related Security Bulletins