First published: Wed Aug 14 2024(Updated: )
Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting Software Development Kit | <6.1.0 | |
Zoom Workplace | <6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42439 has been rated as a medium severity vulnerability due to its potential for privilege escalation.
To fix CVE-2024-42439, update the Zoom Workplace Desktop App and Zoom Meeting SDK for macOS to version 6.1.0 or later.
CVE-2024-42439 affects the Zoom Workplace Desktop App and Zoom Meeting SDK for macOS versions prior to 6.1.0.
CVE-2024-42439 cannot be exploited remotely as it requires local access by a privileged user.
CVE-2024-42439 is classified as an untrusted search path vulnerability which can lead to privilege escalation.