CVE-2024-27246: Zoom Workplace Apps and SDKs - Use After Free
Published Feb 25, 2025
·Updated
Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.
Affected Software
17 affected components
Zoom Workplace Apps and SDKs
Zoom Meeting Software Development Kit Android<5.17.11
Zoom Meeting Software Development Kit Iphone Os<5.17.11
Zoom Meeting Software Development Kit Linux<5.17.11
Zoom Meeting Software Development Kit Macos<5.17.11
Zoom Meeting Software Development Kit Windows<5.17.11
Zoom Rooms Ipados<6.0.0
Zoom Rooms Macos<6.0.0
Zoom Rooms Windows<6.0.0
Zoom Workplace Android<5.17.11
Zoom Workplace Iphone Os<5.17.11
Zoom Workplace Desktop Linux<5.17.11
Zoom Workplace Desktop Macos<5.17.11
Zoom Workplace Desktop Windows<5.17.11
Zoom Workplace Virtual Desktop Infrastructure Windows<5.15.17
Zoom Workplace Virtual Desktop Infrastructure Windows>=5.16.0<5.16.15
Zoom Workplace Virtual Desktop Infrastructure Windows>=5.16.16<5.17.11
Event History
Feb 25, 2025
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27246?
CVE-2024-27246 has been rated as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2024-27246?
To fix CVE-2024-27246, update to the latest version of Zoom Workplace Apps and SDKs as provided in the security bulletin.
3
What can an attacker do with CVE-2024-27246?
An attacker can exploit CVE-2024-27246 to conduct a denial of service attack against Zoom Workplace Apps and SDKs.
4
Is authentication required to exploit CVE-2024-27246?
Yes, exploitation of CVE-2024-27246 requires the attacker to be an authenticated user.
5
Which versions of Zoom are affected by CVE-2024-27246?
CVE-2024-27246 affects all versions of Zoom Workplace Apps and SDKs that are exposed to the vulnerability.