cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-39822,https://securityvulnerability.io/vulnerability/CVE-2024-39822,"Sensitive Information Exposure in Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers","Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.",Zoom,"Rooms Controller,Rooms,Meeting Software Development Kit,Workplace,Workplace Desktop",6.5,MEDIUM,0.0004900000058114529,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42440,https://securityvulnerability.io/vulnerability/CVE-2024-42440,Escalation of Privilege Vulnerability in Zoom Workplace Desktop App for macOS,"Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.",Zoom,"Workplace Desktop,Meeting Software Development Kit,Rooms",6.7,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42437,https://securityvulnerability.io/vulnerability/CVE-2024-42437,Buffer overflow vulnerability in Zoom Workplace products may lead to denial of service,"Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.",Zoom,"Rooms Controller,Rooms,Meeting Software Development Kit,Workplace Virtual Desktop Infrastructure,Workplace Desktop,Workplace",6.5,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42439,https://securityvulnerability.io/vulnerability/CVE-2024-42439,Privilege Escalation Vulnerability in macOS Workplace Desktop App,Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.,Zoom,Zoom Workplace Desktop App For Mac OS And Zoom Meeting Sdk For Mac OS,6.5,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-39823,https://securityvulnerability.io/vulnerability/CVE-2024-39823,Potential Sensitive Information Disclosure in Zoom Workplace Apps,"Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.",Zoom,"Rooms Controller,Rooms,Meeting Software Development Kit,Workplace Virtual Desktop Infrastructure,Workplace Desktop,Workplace",4.9,MEDIUM,0.0004900000058114529,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42438,https://securityvulnerability.io/vulnerability/CVE-2024-42438,Buffer Overflow Vulnerability May Lead to Denial of Service,"Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.",Zoom,"Rooms Controller,Rooms,Meeting Software Development Kit,Workplace Virtual Desktop Infrastructure,Workplace Desktop,Workplace",6.5,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42436,https://securityvulnerability.io/vulnerability/CVE-2024-42436,Zoom Buffer Overflow Vulnerability May Lead to Denial of Service,"Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.",Zoom,"Rooms Controller,Rooms,Meeting Software Development Kit,Workplace Virtual Desktop Infrastructure,Workplace Desktop,Workplace",6.5,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42441,https://securityvulnerability.io/vulnerability/CVE-2024-42441,Zoom Workplace Desktop App for macOS: Privilege Escalation Vulnerability,"Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.",Zoom,"Zoom Workplace Desktop App For Mac OS, Zoom Meeting Sdk For Mac OS, Zoom Rooms Client For Mac OS",6.7,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-39824,https://securityvulnerability.io/vulnerability/CVE-2024-39824,Potential Sensitive Information Disclosure in Zoom Workplace Apps,"Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.",Zoom,"Rooms Controller,Rooms,Meeting Software Development Kit,Workplace Virtual Desktop Infrastructure,Workplace Desktop,Workplace",4.9,MEDIUM,0.0004900000058114529,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-24690,https://securityvulnerability.io/vulnerability/CVE-2024-24690,Zoom Clients Vulnerable to Denial of Service Attacks via Network Access,Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.,Zoom,"Zoom,Meeting Software Development Kit,Video Software Development Kit,Rooms,Vdi Windows Meeting Clients",6.5,MEDIUM,0.0005300000193528831,false,false,false,false,,false,false,2024-02-14T00:15:00.000Z,0 CVE-2024-24691,https://securityvulnerability.io/vulnerability/CVE-2024-24691,Unauthenticated Escalation of Privilege Vulnerability in Zoom Desktop Client for Windows,"A security flaw in various Zoom products, specifically the Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK for Windows, exists due to improper input validation. This vulnerability could enable an unauthenticated user to perform an elevation of privilege attack through network access, potentially compromising sensitive information and user permissions. It is crucial for users and administrators to remain vigilant and apply any security updates provided by Zoom to mitigate this vulnerability.","Zoom Video Communications, Inc.","Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows",9.8,CRITICAL,0.0010499999625608325,false,true,false,false,,true,true,2024-02-14T00:15:00.000Z,9953 CVE-2024-24697,https://securityvulnerability.io/vulnerability/CVE-2024-24697,Untrusted Search Path Vulnerability in Zoom 32 bit Windows Clients Could Lead to Escalation of Privilege,"A vulnerability exists in the 32-bit Windows client of Zoom, stemming from an untrusted search path issue. This flaw allows an authenticated user to leverage local access for privilege escalation. It highlights the importance of ensuring proper security measures and validation of search paths within applications to mitigate potential exploitation.",Zoom,"Vdi Windows Meeting Clients,Rooms,Zoom,Meeting Sdk",7.8,HIGH,0.0004299999854993075,false,false,false,false,,false,false,2024-02-14T00:15:00.000Z,0 CVE-2024-24696,https://securityvulnerability.io/vulnerability/CVE-2024-24696,Improper Input Validation in Zoom Desktop Client and SDK for Windows,"An improper input validation vulnerability exists within the Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK for Windows. This flaw enables an authenticated user to potentially disclose sensitive information through network access, which could compromise user privacy and security. It is critical for users to stay informed about this issue and apply necessary updates to safeguard against potential exploits.",Zoom,"Zoom,Vdi Windows Meeting Clients,Meeting Software Development Kit",6.5,MEDIUM,0.0005200000014156103,false,false,false,false,,false,false,2024-02-14T00:15:00.000Z,0 CVE-2024-24698,https://securityvulnerability.io/vulnerability/CVE-2024-24698,Privileged User May Access Information via Local Access,Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.,Zoom,"Vdi Windows Meeting Clients,Zoom,Meeting Software Development Kit,Rooms",4.4,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-02-14T00:15:00.000Z,0 CVE-2024-24699,https://securityvulnerability.io/vulnerability/CVE-2024-24699,Zoom Clients Vulnerable to Information Disclosure via Network Access,"A business logic error present in various versions of the Zoom client allows an authenticated user to potentially expose sensitive information. This vulnerability is linked to how the application handles network access, posing risks to user privacy and data security. Ensuring the implementation of security updates is crucial for all affected client versions to mitigate the risks associated with this flaw.",Zoom,"Zoom,Vdi Windows Meeting Clients,Rooms,Meeting Sdk",6.5,MEDIUM,0.0005200000014156103,false,false,false,false,,false,false,2024-02-14T00:15:00.000Z,0 CVE-2024-24695,https://securityvulnerability.io/vulnerability/CVE-2024-24695,Improper Input Validation in Zoom Desktop Client and SDK for Windows,"An improper input validation issue in various Windows versions of the Zoom Desktop Client, Zoom VDI Client, and Zoom Meeting SDK can potentially allow an authenticated user to disclose confidential information through network access. This vulnerability may expose sensitive data inadvertently due to inadequate checks on input provided by users, stressing the importance of implementing robust security measures in software development.",Zoom,"Meeting Software Development Kit,Zoom,Vdi Windows Meeting Clients",6.5,MEDIUM,0.0005200000014156103,false,false,false,false,,false,false,2024-02-14T00:15:00.000Z,0 CVE-2023-34115,https://securityvulnerability.io/vulnerability/CVE-2023-34115,,Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.,"Zoom Video Communications, Inc.",Zoom Meeting Sdk,4.3,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2023-06-13T19:15:00.000Z,0 CVE-2023-28603,https://securityvulnerability.io/vulnerability/CVE-2023-28603,Improper Access Control in Zoom's VDI Client Installer,"The Zoom VDI client installer, prior to version 5.14.0, is susceptible to an improper access control vulnerability. This flaw allows a malicious user to potentially gain unauthorized access and delete local files without sufficient permissions, posing a significant risk to user data integrity. Users are encouraged to update to the latest version to mitigate this vulnerability.","Zoom Video Communications, Inc.",Zoom Vdi Windows Meeting Client,7.1,HIGH,0.0004400000034365803,false,false,false,false,,false,false,2023-06-13T18:15:00.000Z,0 CVE-2023-34120,https://securityvulnerability.io/vulnerability/CVE-2023-34120,Improper Privilege Management in Zoom for Windows Clients by Zoom,"A vulnerability in Zoom for Windows, including Zoom Rooms and Zoom VDI prior to version 5.14.0, allows authenticated users to exploit improper privilege management. This could lead to elevated system privileges, enabling them to spawn processes that operate with elevated rights. Such exploitation poses significant security risks, as it may allow unauthorized access to sensitive system functions and data.","Zoom Video Communications, Inc.","Zoom For Windows Client,Zoom Rooms Client For Windows,Zoom Vdi For Windows Meeting Clients",7.8,HIGH,0.0004400000034365803,false,false,false,false,,false,false,2023-06-13T18:15:00.000Z,0 CVE-2023-34121,https://securityvulnerability.io/vulnerability/CVE-2023-34121,Input Validation Flaw in Zoom for Windows and Related Products,"An improper input validation vulnerability in the Zoom for Windows, Zoom Rooms, and Zoom VDI Windows Meeting clients prior to version 5.14.0 has been identified. This security lapse could potentially allow an authenticated user to exploit the flaw and escalate privileges through network access, compromising the application's integrity.","Zoom Video Communications, Inc.","Zoom For Windows,Zoom Rooms Client For Windows,Zoom Vdi For Windows Meeting Clients",8.8,HIGH,0.0011399999493733048,false,false,false,false,,false,false,2023-06-13T18:15:00.000Z,0 CVE-2023-28596,https://securityvulnerability.io/vulnerability/CVE-2023-28596,Local Privilege Escalation in Zoom for macOS Installers,"The Zoom Client for IT Admin on macOS prior to version 5.13.5 has a vulnerability that allows low-privileged users to escalate their privileges during the installation process. This local privilege escalation can be exploited as part of a larger attack chain, allowing attackers to gain root access to the affected system. Organizations using affected versions of Zoom should prioritize updating to the latest version to mitigate this risk.",Zoom,Zoom Client for Meetings for IT Admin macOS installers,7.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2023-03-27T00:00:00.000Z,0 CVE-2023-22883,https://securityvulnerability.io/vulnerability/CVE-2023-22883,Local Privilege Escalation in Zoom for Windows Installers,"The Zoom Client for IT Admin Windows installers prior to version 5.13.5 contain a vulnerability that allows a local low-privileged user to exploit the installation process. Through this exploitation, the user can escalate their privileges to that of the SYSTEM user, potentially granting them access to sensitive system resources and increased control over the system.",Zoom,Zoom Client for Meetings for IT Admin Windows installers,7.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2023-03-16T00:00:00.000Z,0 CVE-2022-28768,https://securityvulnerability.io/vulnerability/CVE-2022-28768,Local Privilege Escalation in Zoom Client Installer for macOS,The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.,Zoom,Zoom Client For Meetings Installer For Mac OS (standard And For It Admin),8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2022-11-17T23:15:00.000Z,0 CVE-2022-28766,https://securityvulnerability.io/vulnerability/CVE-2022-28766,DLL injection in Zoom Windows Clients,Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.,Zoom,"Zoom Client For Meetings For Windows (32-bit),Zoom Vdi Windows Meeting Client For Windows (32-bit),Zoom Rooms For Conference Room For Windows (32-bit)",3.3,LOW,0.0004199999966658652,false,false,false,false,,false,false,2022-11-15T00:00:00.000Z,0 CVE-2022-28764,https://securityvulnerability.io/vulnerability/CVE-2022-28764,Local information exposure in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients,Zoom Rooms For Conference Room (for Android, iOS, Linux, Mac OS, And Windows)",3.3,LOW,0.0004199999966658652,false,false,false,false,,false,false,2022-11-14T21:15:00.000Z,0