First published: Wed Aug 14 2024(Updated: )
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting Software Development Kit | <6.1.0 | |
Zoom meeting software development kit iphone os | <6.1.0 | |
Zoom Meeting Software Development Kit | <6.1.0 | |
Zoom Meeting SDK | <6.1.0 | |
Zoom Rooms | <6.1.0 | |
Zoom Rooms | <6.1.0 | |
Zoom Rooms | <6.1.0 | |
Zoom Rooms Controller | <6.1.0 | |
Zoom Rooms Controller | <6.1.0 | |
Zoom Rooms Controller macos | <6.1.0 | |
Zoom Rooms Controller | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace Virtual Desktop Infrastructure | <5.17.14 | |
Zoom Workplace Virtual Desktop Infrastructure | >=6.0<6.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42437 is classified as a buffer overflow vulnerability that may lead to denial of service.
To fix CVE-2024-42437, upgrade your Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers to version 6.1.0 or above.
CVE-2024-42437 affects multiple Zoom products including Meeting SDKs, Rooms, and Controllers across various platforms.
Yes, CVE-2024-42437 can potentially be exploited via network access by an authenticated user.
No official workaround for CVE-2024-42437 has been provided, so updating to the latest version is recommended.