
Cloud Vulnerability DB
A community-led vulnerabilities database
A buffer overflow vulnerability (CVE-2024-27243) was discovered in Zoom Workplace Apps and SDK's. The vulnerability was reported by Zoom Offensive Security and disclosed on May 14, 2024. This security issue affects multiple Zoom products including Zoom Workplace Desktop Apps for Windows, macOS, and Linux, VDI App for Windows, mobile apps for iOS and Android, and various Meeting SDK versions prior to version 5.17.5 (Zoom Bulletin).
The vulnerability is classified as a buffer overflow issue (CWE-122: Heap-based Buffer Overflow). It received a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability requires network access and authenticated user privileges to exploit (NVD, Zoom Bulletin).
If exploited, this vulnerability could allow an authenticated user to conduct a denial of service attack against affected Zoom applications via network access. The CVSS scoring indicates that while there is no impact on confidentiality or integrity, there is a high impact on availability of the affected systems (Zoom Bulletin).
The vulnerability requires an authenticated user with network access to exploit. The attack complexity is considered low, but privileged access is required, and no user interaction is needed for exploitation, as indicated by the CVSS vector string (NVD).
Users are advised to update to Zoom Workplace Apps and SDK version 5.17.5 or later to address this vulnerability. Zoom has released patches for all affected products and recommends users apply the latest updates available at https://zoom.us/download (Zoom Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."