CVE-2024-39825

HIGH

Zoom Rooms and Workplace < 6.0.0 - Authenticated Heap-based Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.

References (1)

Core 1

Scores

CVSS v3 8.5
EPSS 0.0063
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122 CWE-787
Status published
Products (4)
zoom/rooms < 6.0.0 (3 CPE variants)
zoom/workplace < 6.0.0 (2 CPE variants)
zoom/workplace_desktop < 6.0.0 (3 CPE variants)
zoom/workplace_virtual_desktop_infrastructure < 5.17.13
Published Aug 14, 2024
Tracked Since Feb 18, 2026