CVE-2024-42438: Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers - Buffer Overflow
Published Aug 14, 2024
·Updated
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
Affected Software
18 affected components
Zoom Meeting Software Development Kit Android<6.1.0
Zoom Meeting Software Development Kit Iphone Os<6.1.0
Zoom Meeting Software Development Kit Macos<6.1.0
Zoom Meeting Software Development Kit Windows<6.1.0
Zoom Rooms Ipados<6.1.0
Zoom Rooms Macos<6.1.0
Zoom Rooms Windows<6.1.0
Zoom Rooms Controller Android<6.1.0
Zoom Rooms Controller Linux<6.1.0
Zoom Rooms Controller Macos<6.1.0
Zoom Rooms Controller Windows<6.1.0
Zoom Workplace Android<6.1.0
Zoom Workplace Iphone Os<6.1.0
Zoom Workplace Desktop Linux<6.1.0
Zoom Workplace Desktop Macos<6.1.0
Zoom Workplace Desktop Windows<6.1.0
Zoom Workplace Virtual Desktop Infrastructure Windows<5.17.14
Zoom Workplace Virtual Desktop Infrastructure Windows>=6.0<6.0.11
Event History
Aug 14, 2024
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-42438?
CVE-2024-42438 is considered to have a moderate severity due to the potential for denial of service.
2
How do I fix CVE-2024-42438?
To fix CVE-2024-42438, users should update their affected Zoom applications to the latest versions beyond 6.1.0.
3
Which Zoom products are affected by CVE-2024-42438?
CVE-2024-42438 affects Zoom Meeting SDK, Zoom Video SDK, Zoom Rooms, and various Zoom Workplace apps and controllers.
4
Can CVE-2024-42438 be exploited remotely?
Yes, CVE-2024-42438 can be exploited remotely by authenticated users over network access.
5
Is authentication required to exploit CVE-2024-42438?
Yes, exploitation of CVE-2024-42438 requires authentication as it targets authenticated users.