CVE-2024-24691: Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-24691?
CVE-2024-24691 is considered a critical vulnerability due to its potential for privilege escalation by unauthenticated users.
How do I fix CVE-2024-24691?
To fix CVE-2024-24691, it is essential to update the affected Zoom products to the latest versions that are not vulnerable.
Which versions are affected by CVE-2024-24691?
CVE-2024-24691 affects Zoom Desktop Client versions before 5.16.5, Zoom VDI Client before 5.16.10, and Zoom Rooms before 5.17.0.
Can CVE-2024-24691 be exploited remotely?
Yes, CVE-2024-24691 can be exploited remotely via network access by an unauthenticated user.
Who is affected by CVE-2024-24691?
Users of the affected Zoom software on Windows platforms are at risk of exploitation due to CVE-2024-24691.