CVE-2024-45426
MEDIUMDescription
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| zoom | meeting_software_development_kit |
| zoom | meeting_software_development_kit |
| zoom | meeting_software_development_kit |
| zoom | rooms |
| zoom | rooms |
| zoom | rooms_controller |
| zoom | rooms_controller |
| zoom | rooms_controller |
| zoom | workplace |
| zoom | workplace_desktop |
| zoom | workplace_desktop |
| zoom | workplace_virtual_desktop_infrastructure |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-45426? +
How severe is CVE-2024-45426? +
What products are affected by CVE-2024-45426? +
How do I check if I'm vulnerable to CVE-2024-45426? +
Related Vulnerabilities
HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained …
A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a …
Under certain conditions, access to service libraries is granted to account they should not have access to.
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper …
Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user …
A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other …