Zoom Workplace是美国Zoom公司的一个桌面应用软件。 Zoom Workplace Desktop App、Rooms App和Meeting SDK 6.0.0之前版本存在安全漏洞,该漏洞源于安装程序中存在竞争条件,允许经过身份验证的用户通过本地访问进行特权升级。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Communications, Inc | Zoom Apps and SDKs | before version 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-27240 | 7.1 HIGH | Zoom Apps for Windows - Improper Input Validation |
| CVE-2024-39826 | 6.8 MEDIUM | Zoom Workplace Apps and SDKs - Path traversal |
| CVE-2024-39819 | 6.7 MEDIUM | Zoom Workplace Apps and SDK for Windows - Improper Privilege Management |
| CVE-2024-39821 | 6.6 MEDIUM | Zoom Workplace App for Windows and Zoom Rooms App for Windows - Race Condition |
| CVE-2024-39820 | 6.6 MEDIUM | Zoom Workplace Desktop App for macOS - Uncontrolled Search Path Element |
| CVE-2024-39827 | 5.5 MEDIUM | Zoom Workplace Desktop App for Windows - Improper Input Validation |
| CVE-2024-27241 | 5.3 MEDIUM | Zoom Apps and SDKs - Improper Input Validation |
No comments yet