• News/
  • https://www.theregister.com/2024/02/15/zoom_privilege_escalation/

Zoom stomps critical privilege escalation bug plus 6 other flaws

The Register
·
Connor Jones
·
Published Feb 15, 2024
·
Updated

Video conferencing giant Zoom today opened up about a fresh batch of security vulnerabilities affecting its products, including a critical privilege escalation flaw. Tracked as CVE-2024-24691 with a CVSS score of 9.6, Zoom says the vulnerability may enable privilege escalation for unauthenticated users via network access. Limited technical details were disclosed, but an examination of the exploitability metrics that influenced the severity score shows that Zoom believes an exploit would require little complexity to execute, although some user interaction may be required. It's also deemed to have a potentially high impact on affected products, which include the Windows versions of the Zoom desktop client, VDI client, Rooms client, and Zoom Meeting SDK. Zoom Desktop Client for Windows before version 5.16.5 Zoom VDI Client for Windows before version 5.16.10 (excluding 5.14.14 and 5.15.12) Zoom Rooms Client for Windows before version 5.17.0 Zoom Meeting SDK for Windows before version 5.16.5 The vulnerability was reported by researchers in Zoom's Offensive Security division, and the company hasn't said whether any in-the-wild exploitation was detected. In any case, the severity of the vulnerability should be a cause for concern and prompt users into patching to the latest version. Also included in the round of updates were improper input validation vulnerabilities, as well as assorted others, although these were mostly all medium-severity issues, bar one. The other now-patched vul...

Read full article

Affected Software

9 affected components
Zoom Zoom Desktop Client=before version 5.16.5
Zoom Zoom VDI client=before version 5.16.10 (excluding 5.14.14 and 5.15.12)
Zoom Zoom Rooms Client=before version 5.17.0
Zoom Zoom Meeting SDK=before version 5.16.5
Zoom Zoom desktop apps
Zoom Zoom mobile apps
Zoom Zoom VDI client
Zoom Zoom Rooms Client
Zoom Zoom Meeting SDKs
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical privilege escalation vulnerability discovered in Zoom products and other security flaws reported by Zoom.

2

What security implications are discussed?

The article highlights a critical vulnerability tracked as CVE-2024-24691 with a CVSS score of 9.6, which could allow unauthorized access to user permissions.

3

What products or software are affected?

Affected products include the Zoom Desktop Client, Zoom VDI Client, Zoom Rooms Client, and Zoom Meeting SDK, specifically versions prior to 5.16.5, 5.16.10, and 5.17.0.

4

What actions has Zoom taken in response to the vulnerabilities?

Zoom has released updates to fix the identified vulnerabilities in their affected products.

5

How can users mitigate the risks associated with these vulnerabilities?

Users can mitigate risks by updating their Zoom software to the latest versions provided by Zoom to close the security gaps.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203