CVE-2024-39825

HIGH

Zoom Rooms < 6.0.0 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

References (1)

Core 1

Scores

CVSS v3 8.5
EPSS 0.0130
EPSS Percentile 79.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122 CWE-787
Status published
Products (4)
zoom/rooms < 6.0.0 (3 CPE variants)
zoom/workplace < 6.0.0 (2 CPE variants)
zoom/workplace_desktop < 6.0.0 (3 CPE variants)
zoom/workplace_virtual_desktop_infrastructure < 5.17.13
Published Aug 14, 2024
Tracked Since Feb 18, 2026