Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
History

Thu, 29 Aug 2024 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Zoom meeting Software Development Kit
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
Vendors & Products Zoom meeting Software Development Kit

Wed, 14 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Zoom
Zoom macos Meeting Sdk
Zoom rooms
Zoom workplace Desktop
CPEs cpe:2.3:a:zoom:macos_meeting_sdk:*:*:*:*:*:*:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
Vendors & Products Zoom
Zoom macos Meeting Sdk
Zoom rooms
Zoom workplace Desktop
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Description Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
Title Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Improper Privilege Management
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published: 2024-08-14T16:44:46.080Z

Updated: 2024-08-14T18:06:25.844Z

Reserved: 2024-08-01T19:13:16.137Z

Link: CVE-2024-42440

cve-icon Vulnrichment

Updated: 2024-08-14T18:06:10.933Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-14T17:15:17.757

Modified: 2024-08-28T23:59:01.537

Link: CVE-2024-42440

cve-icon Redhat

No data.