Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53926 | Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-24040/ |
|
History
Tue, 04 Mar 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom
Zoom meeting Software Development Kit Zoom rooms Zoom video Software Development Kit Zoom workplace Desktop |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:* |
|
| Vendors & Products |
Zoom
Zoom meeting Software Development Kit Zoom rooms Zoom video Software Development Kit Zoom workplace Desktop |
Tue, 25 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Title | Zoom Apps for macOS - Symbolic Link Following | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-02-25T20:07:09.959Z
Reserved: 2024-08-28T21:50:25.332Z
Link: CVE-2024-45418
Updated: 2025-02-25T20:07:06.495Z
Status : Analyzed
Published: 2025-02-25T20:15:35.223
Modified: 2025-03-04T17:22:39.620
Link: CVE-2024-45418
No data.
OpenCVE Enrichment
No data.
EUVD