Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
History

Tue, 04 Mar 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom video Software Development Kit
Zoom workplace Desktop
Weaknesses CWE-59
CPEs cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
Vendors & Products Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom video Software Development Kit
Zoom workplace Desktop

Tue, 25 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 20:00:00 +0000

Type Values Removed Values Added
Description Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
Title Zoom Apps for macOS - Symbolic Link Following
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2025-02-25T20:07:09.959Z

Reserved: 2024-08-28T21:50:25.332Z

Link: CVE-2024-45418

cve-icon Vulnrichment

Updated: 2025-02-25T20:07:06.495Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T20:15:35.223

Modified: 2025-03-04T17:22:39.620

Link: CVE-2024-45418

cve-icon Redhat

No data.