Zoom Video Communications is warning that Zoom desktop and VDI clients and the Meeting SDK for Windows are vulnerable to a vulnerability that could allow an unauthorized attacker to gain privilege escalation on the system.

Zoom has become one of the most popular video conferencing services during the pandemic. It is cloud-based and is used by users around the world for corporate meetings, training courses, social interactions, and more. It offers various features that enable effective digital communication and collaboration.
The vulnerability recently disclosed by the company, tracked as CVE-2024-24691 and discovered by Zoom's own security team, is considered " critical " with a CVSS v3.1 score of 9.6/10.
See also: Microsoft Patch Tuesday February 2024: 73 vulnerabilities fixed
The vulnerability affects the following product versions:
- Zoom Desktop Client for Windows before version 5.16.5
- Zoom VDI Client for Windows prior to version 5.16.10 (excluding 5.14.14 and 5.15.12)
- Zoom Rooms Client for Windows before version 5.17.0
- Zoom Meeting SDK for Windows before version 5.16.5
Zoom did not provide details on how the vulnerability is exploited or the impact, but it appears that some interaction user. This could include clicking on a link, opening an attached file, or performing some other action that an attacker could leverage to exploit the CVE-2024-24691 vulnerability.
Zoom displays an automatic notification to users to update their software to the latest version. However, one can download and install the latest version of the desktop client for Windows, version 5.17.7, manually.
It is worth noting that the immediate implementation of the update is necessary because in addition to the above critical vulnerability, six other vulnerabilities are also fixed.
See also: CISA: Adds Chrome vulnerability to KEV List
- CVE-2024-24697: A very serious vulnerability in Zoom 32-bit Windows clients allows elevation of privilege via local access.
- CVE-2024-24696: This is an in-meeting chat issue in Zoom Windows clients, caused by improper input validation and allowing information disclosure over the network.
- CVE-2024-24695: Similar to CVE-2024-24696, improper input validation in Zoom Windows clients allows information disclosure over the network.
- CVE-2024-24699: A business logic error in the in-meeting chat feature that could lead to information disclosure over the network.
- CVE-2024-24690: The vulnerability is found in certain Zoom clients and is caused by improper input validation. It can cause a denial of service over the network.
- CVE-2024-24698: A vulnerability that allows information disclosure through local access by privileged users.

Protection
Considering the above vulnerabilities, Zoom users should apply the security update as soon as possible to reduce the chances of a breach.
See also: New vulnerabilities in Cisco, Fortinet, VMware require immediate updates
Next, it's helpful to have a reliable antivirus program installed on your device . This can help detect and prevent attacks before they cause damage.
Finally, use a firewall to control incoming and outgoing traffic on your network. This can help prevent attacks before they reach your system.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
