First published: Wed Aug 14 2024(Updated: )
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting Software Development Kit | <6.1.0 | |
Zoom meeting software development kit iphone os | <6.1.0 | |
Zoom Meeting Software Development Kit | <6.1.0 | |
Zoom Meeting SDK | <6.1.0 | |
Zoom Rooms | <6.1.0 | |
Zoom Rooms | <6.1.0 | |
Zoom Rooms | <6.1.0 | |
Zoom Rooms Controller | <6.1.0 | |
Zoom Rooms Controller | <6.1.0 | |
Zoom Rooms Controller macos | <6.1.0 | |
Zoom Rooms Controller | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace | <6.1.0 | |
Zoom Workplace Virtual Desktop Infrastructure | <5.17.14 | |
Zoom Workplace Virtual Desktop Infrastructure | >=6.0<6.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42438 is considered to have a moderate severity due to the potential for denial of service.
To fix CVE-2024-42438, users should update their affected Zoom applications to the latest versions beyond 6.1.0.
CVE-2024-42438 affects Zoom Meeting SDK, Zoom Video SDK, Zoom Rooms, and various Zoom Workplace apps and controllers.
Yes, CVE-2024-42438 can be exploited remotely by authenticated users over network access.
Yes, exploitation of CVE-2024-42438 requires authentication as it targets authenticated users.