CVE-2024-24699
MEDIUMDescription
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.
Is your site exposed to CVE-2024-24699?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| zoom | meeting_sdk |
| zoom | rooms |
| zoom | vdi_windows_meeting_clients |
| zoom | vdi_windows_meeting_clients |
| zoom | vdi_windows_meeting_clients |
| zoom | zoom |
| zoom | zoom |
| zoom | zoom |
| zoom | zoom |
| zoom | zoom |
References
Frequently Asked Questions
What is CVE-2024-24699? +
How severe is CVE-2024-24699? +
What products are affected by CVE-2024-24699? +
How do I check if I'm vulnerable to CVE-2024-24699? +
Related Vulnerabilities
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows …
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege …
Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation …
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before …
Time-of-check time-of-use race condition in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege …
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.