Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Zoom Patches Critical Vulnerability in Windows Applications

Zoom patches seven vulnerabilities in its products, including a critical-severity bug in its Windows applications.

Zoom vulnerabilities

Video messaging giant Zoom on Tuesday announced patches for seven vulnerabilities in its desktop and mobile applications, including a critical-severity bug in Windows software.

The critical issue, tracked as CVE-2024-24691 (CVSS score of 9.6), is described as an improper input validation that could allow an attacker with network access to escalate privileges.

Zoom’s Desktop Client for Windows before version 5.16.5, VDI Client for Windows before version 5.16.10 (excluding 5.14.14 and 5.15.12), Rooms Client for Windows before version 5.17.0, and Meeting SDK for Windows before version 5.16.5 are affected, the company notes in its advisory.

The video messaging company also resolved a high-severity escalation of privilege defect in these Windows applications, noting that it can be exploited locally, without authentication.

Tracked as CVE-2024-24697 and described as an untrusted search path issue, the vulnerability impacts Desktop Client before version 5.17.0, VDI Client before version 5.17.5 (excluding 5.15.15 and 5.16.12), Meeting SDK before version 5.17.0, and Rooms Client before version 5.17.0.

Two medium-severity flaws leading to information leaks were also resolved in the Desktop Client, VDI Client, and Meeting SDK for Windows.

Advertisement. Scroll to continue reading.

On Tuesday, the company also warned that three medium-severity vulnerabilities in the Zoom clients for desktop and mobile platforms could be exploited to conduct denial-of-service attacks or to leak information.

Zoom users on Windows, macOS, Linux, Android, and iOS are advised to update their applications to the latest available releases.

The company makes no mention of any of these vulnerabilities being exploited in malicious attacks. Additional information on the bugs can be found on Zoom’s security bulletins page.

Related: Intel, AMD, Zoom, Splunk Release Patch Tuesday Security Advisories

Related: Zoom Unveils Open Source Vulnerability Impact Scoring System

Related: Zoom Patches High Risk Flaws on Windows, MacOS Platforms

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.