QID 379383
Date Published: 2024-02-21
QID 379383: Zoom Desktop Client and Zoom VDI Client for Windows Improper Input Validation Vulnerability (ZSB-24002, ZSB-24003)
Zoom has released a security update for Zoom to fix the vulnerabilities.
CVE-2024-24695: Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
CVE-2024-24696: Improper input validation with in-meeting chat for Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access.
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom Client prior to version 5.17.0(Windows), 5.17.5(Windows), 5.17.0(Windows)
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
CVEs related to QID 379383
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-24002 |
|