CVE-2024-42439
Zoom
CVE-2024-42439 is a vulnerability in the Zoom Workplace Desktop App and Zoom Meeting SDK for macOS. Specifically, an untrusted search path within the installer before version 6.1.0 could be exploited by a privileged local user to escalate their privileges. This privilege escalation vulnerability allows attackers with existing local access to gain higher-level permissions on the system. While the CVSS score is 6.5, the SOCRadar Vulnerability Risk Score (SVRS) is 61, indicating a moderate level of risk. Although not critical (SVRS > 80), it should still be addressed promptly. Exploiting this security flaw could lead to unauthorized access and control over the affected macOS system. Users should update to version 6.1.0 or later to mitigate this risk.
Description
CVE-2024-42439 is a vulnerability in the installer for Zoom Workplace Desktop App and Zoom Meeting SDK for macOS before version 6.1.0. This vulnerability allows a privileged user to escalate privileges via local access due to an untrusted search path. The SVRS for this vulnerability is 34, indicating a moderate risk.
Key Insights
- This vulnerability can be exploited by a privileged user with local access to the target system.
- The vulnerability could allow an attacker to gain elevated privileges on the target system.
- This vulnerability is not currently being actively exploited in the wild.
- CISA has not issued a warning for this vulnerability.
Mitigation Strategies
- Update Zoom Workplace Desktop App and Zoom Meeting SDK for macOS to version 6.1.0 or later.
- Restrict access to the target system to only authorized users.
- Implement a least privilege policy on the target system.
- Monitor the target system for any suspicious activity.
Additional Information
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.