← back
CVE-2024-24691criticalCWE-176

Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.6epss 1.7%
exploitation probability
1.7%top 25% of all CVEs
observed exploitation
nono source reports it
In short

The Zoom Desktop Client for Windows fails to properly check user inputs, allowing someone on the network to gain higher privileges without needing to log in first. This is a serious flaw because it can let attackers take control of the application or the system.

Technical detail

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client, and Meeting SDK for Windows enables unauthenticated privilege escalation via network vector. The vulnerability stems from insufficient sanitization of network-supplied inputs, allowing an attacker with network access to bypass authentication controls and elevate their privileges within the affected application.

Summary generated and translated by AI from the official description.
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H