4.4

CVE-2024-24698

Zoom Clients - Improper Authentication

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meeting Software Development Kit SwPlatform windows Version < 5.17.0
Zoom ≫ Rooms SwPlatform windows Version < 5.17.0
Zoom ≫ Vdi Windows Meeting Clients SwPlatform windows Version < 5.15.5
Zoom ≫ Vdi Windows Meeting Clients SwPlatform windows Version > 5.15.15 < 5.16.12
Zoom ≫ Vdi Windows Meeting Clients SwPlatform windows Version > 5.16.12 < 5.17.5
Zoom ≫ Zoom SwPlatform android Version < 5.17.0
Zoom ≫ Zoom SwPlatform iphone_os Version < 5.17.0
Zoom ≫ Zoom SwPlatform linux Version < 5.17.0
Zoom ≫ Zoom SwPlatform macos Version < 5.17.0
Zoom ≫ Zoom SwPlatform windows Version < 5.17.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.405
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
security@zoom.us 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-449 The UI Performs the Wrong Action

The UI performs the wrong action with respect to the user's request.

https://www.zoom.com/en/trust/security-bulletin/ZSB-24005/
Vendor Advisory