CVE-2024-24697
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2024-24697 is a newly disclosed vulnerability affecting some 32-bit Zoom clients on Windows. This issue stems from an untrusted search path, which can be exploited by authenticated users to escalate privileges and gain higher access levels within the application. This local vulnerability can potentially allow attackers to elevate their status from standard user to administrator, posing a significant risk to the security of the affected system. It is essential that users update their Zoom clients to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.