CVE-2024-27238: Zoom Apps and SDKs - Race Condition
Published Jul 15, 2024
·Updated
Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.
Affected Software
4 affected components
Zoom Apps and SDKs<6.0.0
Zoom Meeting Software Development Kit Windows<6.0.0
Zoom Rooms Windows<6.0.0
Zoom Workplace Desktop Windows<6.0.0
Event History
Jul 15, 2024
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27238?
CVE-2024-27238 has been classified as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-27238?
To fix CVE-2024-27238, users should upgrade to Zoom Apps and SDKs version 6.0.0 or later.
3
What type of vulnerability is CVE-2024-27238?
CVE-2024-27238 is a race condition vulnerability that affects the installer for certain Zoom Apps and SDKs.
4
Who is affected by CVE-2024-27238?
Authenticated users of Zoom Apps and SDKs on Windows versions before 6.0.0 are affected by CVE-2024-27238.
5
Can CVE-2024-27238 be exploited remotely?
CVE-2024-27238 requires local access to be exploited, as it is not a remotely exploitable vulnerability.