First published: Tue Feb 13 2024(Updated: )
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Desktop Client | =before version 5.16.5 | |
Zoom Client for Meetings | =before version 5.16.10 (excluding 5.14.14 and 5.15.12) | |
Zoom Rooms | =before version 5.17.0 | |
Zoom Zoom Meeting SDK | =before version 5.16.5 | |
Zoom Desktop Client | ||
Zoom Zoom mobile apps | ||
Zoom Client for Meetings | ||
Zoom Rooms | ||
Zoom Zoom Meeting SDK | ||
Zoom Zoom Meeting SDK | <5.16.5 | |
Zoom Rooms | <5.17.0 | |
Zoom Client for Meetings | <5.15.15 | |
Zoom Client for Meetings | >5.15.15<5.16.10 | |
Zoom Client for Meetings | >5.16.10<5.17.5 | |
Zoom | <5.16.5 | |
Zoom | <5.16.5 | |
Zoom Zoom Linux kernel | <5.16.5 | |
Zoom | <5.16.5 | |
Zoom | <5.16.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-24699 is classified as a business logic error that can lead to information disclosure.
To fix CVE-2024-24699, users should update their Zoom clients to versions 5.16.5 or newer.
CVE-2024-24699 affects Zoom Desktop Client before version 5.16.5, Zoom VDI Client before version 5.16.10, and Zoom Rooms Client before version 5.17.0.
CVE-2024-24699 requires an authenticated user to exploit the vulnerability, thus it's not remotely exploitable.
CVE-2024-24699 may allow an authenticated user to access sensitive information through network access.