Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.

Subscriptions

Vendors Products
Meeting Software Development Kit Subscribe
Video Software Development Kit Subscribe
Workplace Desktop Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-53899 Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Mar 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom video Software Development Kit
Zoom workplace Desktop
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
Vendors & Products Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom video Software Development Kit
Zoom workplace Desktop

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 20:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.
Title Zoom Apps for macOS - Uncontrolled Resource Consumption
Weaknesses CWE-708
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2025-02-26T16:42:11.552Z

Reserved: 2024-08-28T21:50:25.332Z

Link: CVE-2024-45417

cve-icon Vulnrichment

Updated: 2025-02-26T16:41:57.550Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T20:15:35.007

Modified: 2025-03-04T17:22:39.620

Link: CVE-2024-45417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses