Zoom Security Updates – 13 March 2024

Zoom has released security updates to fix two vulnerabilities across Zoom Rooms Client for Windows before version 5.17.5.

The addressed vulnerabilities could allow the local authenticated attacker to trigger denial of service attacks on the affected system by sending a specially crafted request.

Sample of the addressed vulnerabilities:

Zoom Rooms Client for Windows Denial of Service Vulnerability (CVE-2024-24693):

  • CVSS: 7.2
  • Attack Vector: Local
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Denial of Service
Vulnerabilities
  • CVE-2024-24693
  • CVE-2024-24692
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisory

References