CVE Vulnerabilities

CVE-2024-27244

Improper Verification of Cryptographic Signature

Published: May 15, 2024 | Modified: Aug 21, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Workplace_virtual_desktop_infrastructure Zoom * 5.15.0 (excluding)
Workplace_virtual_desktop_infrastructure Zoom 5.16.0 (including) 5.17.10 (excluding)

References