CVE Vulnerabilities

CVE-2024-24698

The UI Performs the Wrong Action

Published: Feb 14, 2024 | Modified: Nov 21, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

Weakness

The UI performs the wrong action with respect to the user’s request.

Affected Software

NameVendorStart VersionEnd Version
Meeting_software_development_kitZoom*5.17.0 (excluding)
RoomsZoom*5.17.0 (excluding)
Vdi_windows_meeting_clientsZoom*5.15.5 (excluding)
Vdi_windows_meeting_clientsZoom5.15.15 (excluding)5.16.12 (excluding)
Vdi_windows_meeting_clientsZoom5.16.12 (excluding)5.17.5 (excluding)
ZoomZoom*5.17.0 (excluding)

References