Cobalt Strike Malware – Active IOCs
August 20, 2024An Emerging Ducktail Infostealer – Active IOCs
August 21, 2024Cobalt Strike Malware – Active IOCs
August 20, 2024An Emerging Ducktail Infostealer – Active IOCs
August 21, 2024Severity
High
Analysis Summary
CVE-2024-39818 CVSS:7.5
Multiple Zoom products could allow a remote authenticated attacker to obtain sensitive information. By sending a specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVE-2024-39825 CVSS:8.5
Multiple Zoom products could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a buffer overflow flaw, By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.
Impact
- Privilege Escalation
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2024-39818
- CVE-2024-39825
Affected Vendors
Affected Products
- Zoom Meeting SDK for Windows
- Zoom Workplace Desktop App for Linux
- Zoom Workplace App for iOS
- Zoom Rooms App for Windows
- Zoom Workplace VDI Client for Windows
- Zoom Workplace App for iOS and Android
Remediation
Refer to Zoom Security Advisory for patch, upgrade or suggested workaround information.