CVE-2024-27246

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 25, 2025
CWE ID 416

Summary

CVE-2024-27246 is a recently disclosed vulnerability affecting some Zoom Workplace Apps and Software Development Kits (SDKs). This issue involves a use-after-free condition, which allows an authenticated user to execute a denial-of-service (DoS) attack via network access. The vulnerability is triggered when the application fails to correctly manage memory, resulting in a potential memory corruption. This can cause the affected application to crash or become unresponsive, effectively carrying out a DoS attack. Zoom has released patches to address this issue and urges users to apply the updates promptly to mitigate potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share