First published: Tue Feb 13 2024(Updated: )
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting SDK | <5.16.5 | |
Zoom Client for Meetings | <5.15.15 | |
Zoom Client for Meetings | >5.15.15<5.16.12 | |
Zoom Client for Meetings | >5.16.12<5.17.5 | |
Zoom | <5.16.5 | |
Zoom Desktop Client | =before version 5.16.5 | |
Zoom Client for Meetings | =before version 5.16.10 (excluding 5.14.14 and 5.15.12) | |
Zoom Rooms | =before version 5.17.0 | |
Zoom Zoom Meeting SDK | =before version 5.16.5 | |
Zoom Desktop Client | ||
Zoom Zoom mobile apps | ||
Zoom Client for Meetings | ||
Zoom Rooms | ||
Zoom Zoom Meeting SDK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-24695 has been classified with a severity level that could allow information disclosure via improper input validation.
To fix CVE-2024-24695, update the affected Zoom Desktop Client, VDI Client, or Meeting SDK to the latest available version.
CVE-2024-24695 affects Zoom products prior to versions 5.16.5 for the Desktop Client and Meeting SDK, and various earlier versions for the VDI Client.
Authenticated users of affected Zoom applications can be impacted by CVE-2024-24695 due to potential information disclosure.
The implications of CVE-2024-24695 include potential unauthorized disclosure of information through network access in affected Zoom products.