Improper privilege management in Zoom Rooms Client for macOS and Zoom Workplace Desktop App for macOS - CVE-2024-42442
Published: August 13, 2024
Vulnerability identifier: #VU95823
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42442
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper privilege management. A local user can escalate privileges on the system.
Affected software
Zoom Rooms Client for macOS
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for macOS
How to mitigate CVE-2024-42442
Install updates from vendor's website.
Zoom Rooms Client for macOS - update to 6.1.5 7039
Zoom Workplace Desktop App for macOS - update to 6.1.5 37534
Zoom Workplace Desktop App for macOS - update to 6.1.5 37534