Rewterz
Cobalt Strike Malware – Active IOCs
August 20, 2024
Rewterz
An Emerging Ducktail Infostealer – Active IOCs
August 21, 2024

Multiple Zoom Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-39818 CVSS:7.5

Multiple Zoom products could allow a remote authenticated attacker to obtain sensitive information. By sending a specially crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.

CVE-2024-39825 CVSS:8.5

Multiple Zoom products could allow a remote authenticated attacker to gain elevated privileges on the system, caused by a buffer overflow flaw, By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privileges.

Impact

  • Privilege Escalation
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2024-39818
  • CVE-2024-39825

Affected Vendors

Zoom

Affected Products

  • Zoom Meeting SDK for Windows
  • Zoom Workplace Desktop App for Linux
  • Zoom Workplace App for iOS
  • Zoom Rooms App for Windows
  • Zoom Workplace VDI Client for Windows
  • Zoom Workplace App for iOS and Android

Remediation

Refer to Zoom Security Advisory for patch, upgrade or suggested workaround information.

CVE-2024-39818

CVE-2024-39825