Description
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
Published: 2025-02-25
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-53926 Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
History

Tue, 04 Mar 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom video Software Development Kit
Zoom workplace Desktop
Weaknesses CWE-59
CPEs cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
Vendors & Products Zoom
Zoom meeting Software Development Kit
Zoom rooms
Zoom video Software Development Kit
Zoom workplace Desktop

Tue, 25 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 20:00:00 +0000

Type Values Removed Values Added
Description Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
Title Zoom Apps for macOS - Symbolic Link Following
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Zoom Meeting Software Development Kit Rooms Video Software Development Kit Workplace Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2025-02-25T20:07:09.959Z

Reserved: 2024-08-28T21:50:25.332Z

Link: CVE-2024-45418

cve-icon Vulnrichment

Updated: 2025-02-25T20:07:06.495Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T20:15:35.223

Modified: 2025-03-04T17:22:39.620

Link: CVE-2024-45418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses