CVE-2024-27243
Zoom Client vulnerability analysis and mitigation

Overview

A buffer overflow vulnerability (CVE-2024-27243) was discovered in Zoom Workplace Apps and SDK's. The vulnerability was reported by Zoom Offensive Security and disclosed on May 14, 2024. This security issue affects multiple Zoom products including Zoom Workplace Desktop Apps for Windows, macOS, and Linux, VDI App for Windows, mobile apps for iOS and Android, and various Meeting SDK versions prior to version 5.17.5 (Zoom Bulletin).

Technical details

The vulnerability is classified as a buffer overflow issue (CWE-122: Heap-based Buffer Overflow). It received a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability requires network access and authenticated user privileges to exploit (NVD, Zoom Bulletin).

Impact

If exploited, this vulnerability could allow an authenticated user to conduct a denial of service attack against affected Zoom applications via network access. The CVSS scoring indicates that while there is no impact on confidentiality or integrity, there is a high impact on availability of the affected systems (Zoom Bulletin).

Exploitability

The vulnerability requires an authenticated user with network access to exploit. The attack complexity is considered low, but privileged access is required, and no user interaction is needed for exploitation, as indicated by the CVSS vector string (NVD).

Mitigation and workarounds

Users are advised to update to Zoom Workplace Apps and SDK version 5.17.5 or later to address this vulnerability. Zoom has released patches for all affected products and recommends users apply the latest updates available at https://zoom.us/download (Zoom Bulletin).

Additional resources


SourceThis report was generated using AI

Related Zoom Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-53412CRITICAL9.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:zoom:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026
CVE-2026-30903CRITICAL9.8
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:zoom
NoYesMar 11, 2026
CVE-2026-53415HIGH8.3
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:virtual_desktop_infrastructure:*:*:*:*:*:windows:*:*
NoYesAug 11, 2026
CVE-2026-53413HIGH8.3
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:zoom
NoYesAug 11, 2026
CVE-2026-53410HIGH7
  • Zoom Client logoZoom Client
  • cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
NoYesJul 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management