CVE-2024-24698: Zoom Clients - Improper Authentication
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-24698?
CVE-2024-24698 has been assigned a medium severity rating due to its potential for improper authentication allowing information disclosure.
How do I fix CVE-2024-24698?
To fix CVE-2024-24698, you should update your Zoom clients to the latest versions available, specifically beyond 5.17.0 for most products.
Which Zoom products are affected by CVE-2024-24698?
CVE-2024-24698 affects multiple Zoom products including Zoom Desktop Client, Zoom Rooms, and various versions of the Zoom Mobile Apps.
Is local access required to exploit CVE-2024-24698?
Yes, exploitation of CVE-2024-24698 requires local access to the vulnerable Zoom client.
What type of vulnerability is CVE-2024-24698?
CVE-2024-24698 is classified as an improper authentication vulnerability that could lead to unauthorized information disclosure.