Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39625 | Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. |
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-24034 |
|
Thu, 29 Aug 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom meeting Software Development Kit
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:* | |
| Vendors & Products |
Zoom meeting Software Development Kit
|
Wed, 14 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom
Zoom macos Meeting Sdk Zoom rooms Zoom workplace Desktop |
|
| CPEs | cpe:2.3:a:zoom:macos_meeting_sdk:*:*:*:*:*:*:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:* |
|
| Vendors & Products |
Zoom
Zoom macos Meeting Sdk Zoom rooms Zoom workplace Desktop |
|
| Metrics |
ssvc
|
Wed, 14 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. | |
| Title | Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS, Zoom Rooms Client for macOS - Improper Privilege Management | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2024-08-14T18:06:25.844Z
Reserved: 2024-08-01T19:13:16.137Z
Link: CVE-2024-42440
Updated: 2024-08-14T18:06:10.933Z
Status : Analyzed
Published: 2024-08-14T17:15:17.757
Modified: 2024-08-28T23:59:01.537
Link: CVE-2024-42440
No data.
OpenCVE Enrichment
No data.
EUVD