CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-42439

High Severity
Zoom
SVRS
61/100

CVSSv3
6.5/10

EPSS
0.00022/1

CVE-2024-42439 is a vulnerability in the Zoom Workplace Desktop App and Zoom Meeting SDK for macOS. Specifically, an untrusted search path within the installer before version 6.1.0 could be exploited by a privileged local user to escalate their privileges. This privilege escalation vulnerability allows attackers with existing local access to gain higher-level permissions on the system. While the CVSS score is 6.5, the SOCRadar Vulnerability Risk Score (SVRS) is 61, indicating a moderate level of risk. Although not critical (SVRS > 80), it should still be addressed promptly. Exploiting this security flaw could lead to unauthorized access and control over the affected macOS system. Users should update to version 6.1.0 or later to mitigate this risk.

No tags available
CVSS:3.1
AV:L
AC:L
PR:H
UI:R
S:U
C:H
I:H
A:H
2024-08-14

2024-08-29
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-42439 is a vulnerability in the installer for Zoom Workplace Desktop App and Zoom Meeting SDK for macOS before version 6.1.0. This vulnerability allows a privileged user to escalate privileges via local access due to an untrusted search path. The SVRS for this vulnerability is 34, indicating a moderate risk.

Key Insights

  • This vulnerability can be exploited by a privileged user with local access to the target system.
  • The vulnerability could allow an attacker to gain elevated privileges on the target system.
  • This vulnerability is not currently being actively exploited in the wild.
  • CISA has not issued a warning for this vulnerability.

Mitigation Strategies

  • Update Zoom Workplace Desktop App and Zoom Meeting SDK for macOS to version 6.1.0 or later.
  • Restrict access to the target system to only authorized users.
  • Implement a least privilege policy on the target system.
  • Monitor the target system for any suspicious activity.

Additional Information

If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

CVE-2024-42439 Local Privilege Escalation in Zoom macOS Apps Below 6.1.0 The installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS (before version 6.1.0) has an untrusted search path. ... https://t.co/kZqYMcM0MC
0
0
1
CVE-2024-42439 Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an … https://t.co/7LiYPzVigi
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppZoommeeting_software_development_kit

References

ReferenceLink
[email protected]https://www.zoom.com/en/trust/security-bulletin/zsb-24032

CWE Details

CWE IDCWE NameDescription
CWE-426Untrusted Search PathThe application searches for critical resources using an externally-supplied search path that can point to resources that are not under the application's direct control.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence