CVE-2024-24697

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 14, 2024
CWE ID 426

Summary

CVE-2024-24697 is a newly disclosed vulnerability affecting some 32-bit Zoom clients on Windows. This issue stems from an untrusted search path, which can be exploited by authenticated users to escalate privileges and gain higher access levels within the application. This local vulnerability can potentially allow attackers to elevate their status from standard user to administrator, posing a significant risk to the security of the affected system. It is essential that users update their Zoom clients to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share