CVE-2024-45418: Zoom Apps for macOS - Symbolic Link Following
Published Feb 25, 2025
·Updated
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
Affected Software
5 affected components
Zoom Meeting Software Development Kit Macos<6.1.5
Zoom Rooms Macos<6.1.5
Zoom Video Software Development Kit Macos<6.1.5
Zoom Workplace Desktop Macos<6.1.5
Zoom Apps for macOS<6.1.5
Event History
Feb 25, 2025
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-45418?
The severity of CVE-2024-45418 has not been specifically rated, but it can lead to privilege escalation if exploited.
2
How do I fix CVE-2024-45418?
To mitigate CVE-2024-45418, upgrade to Zoom Apps for macOS version 6.1.5 or later.
3
What types of users are affected by CVE-2024-45418?
Authenticated users of Zoom Apps for macOS versions prior to 6.1.5 are affected by CVE-2024-45418.
4
What kind of attack does CVE-2024-45418 enable?
CVE-2024-45418 enables authenticated users to conduct an escalation of privilege via network access.
5
When was CVE-2024-45418 disclosed?
CVE-2024-45418 was disclosed in a security bulletin related to Zoom Apps for macOS.