CVE-2024-39826

MEDIUM

Zoom Meeting SDK < 6.0.0 - Authenticated Information Disclosure via Team Chat Race Condition

Title source: llm
STIX 2.1

Description

Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network access.

References (1)

Core 1

Scores

CVSS v3 6.8
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367 CWE-22
Status published
Products (3)
zoom/meeting_software_development_kit < 6.0.0
zoom/workplace_desktop < 6.0.0
zoom/workplace_virtual_desktop_infrastructure < 5.17.13
Published Jul 15, 2024
Tracked Since Feb 18, 2026