Vulnerability Report

Two High Severity Bugs Fixed in Recent Zoom Update

By

Matthew Fagan, Vulnerability Management Patch Analyst

By

Access Point Consulting

Summary

On 08/13/2024, Zoom issued security advisories urging users to patch two high severity vulnerabilities: CVE-2024-39818 (CVSSv3: 7.5), an information disclosure vulnerability that allows an authenticated user to perform information disclosure through network access and CVE-2024-39825 (CVSSv3: 8.5), a buffer overflow that allows an authenticated user to conduct an escalation of privilege using network access. The affected applications are Zoom Workplace Desktop App, Zoom Workplace VDI Client, Zoom Workplace App for Android and iOS, and Zoom Rooms Application for Windows, Mac, and iPad.

Impact

Only attackers authenticated to one of the affected Zoom applications could exploit these vulnerabilities, but if exploited, the vulnerabilities would enable an attacker to perform information disclosure and/or privilege escalation on the affected system. No evidence exists indicating the bugs were exploited or that proof-of-concept code is publicly available.

Affected Applications

CVE-2024-39818

  • Zoom Workplace App for iOS before version 6.0.10
  • Zoom Workplace Desktop App for Linux before version 6.0.10
  • Zoom Workplace Desktop App for Windows before version 6.0.10
  • Zoom Workplace Desktop App for macOS before version 6.0.10
  • Zoom Workplace VDI Client for Windows before version 5.17.13
  • Zoom Meeting SDK for Windows before version 6.0.10
  • Zoom Meeting SDK for iOS before version 6.0.10
  • Zoom Meeting SDK for Android before version 6.0.10
  • Zoom Meeting SDK for macOS before version 6.0.10
  • Zoom Meeting SDK for Linux before version 6.0.10

CVE-2024-39825

  • Zoom Workplace Desktop App for Linux before version 6.0.0
  • Zoom Workplace Desktop App for Windows before version 6.0.0
  • Zoom Workplace Desktop App for macOS before version 6.0.0
  • Zoom Workplace VDI Client for Windows before version 5.17.13
  • Zoom Workplace App for iOS before version 6.0.0
  • Zoom Workplace App for Android before version 6.0.0
  • Zoom Rooms App for Windows before version 6.0.0
  • Zoom Rooms App for Mac before version 6.0.0
  • Zoom Rooms App for iPad before version 6.0.0

Remediation

Applying the latest updates as advised by the vendor is the remediation method. Zoom also has auto-update features in place which could be enabled to keep these applications up-to-date

Recommendations

Patch: We advise you to update the affected application(s) to the latest version at a normal priority. These vulnerabilities are not very high risk and can be mitigated through multifactor authentication.

Auto-update: It is always advised to implement automation to help with vulnerability remediation. In this case, setting up auto updating for these applications will assist in expediting any type of patch these applications would experience.  This should be discussed with leadership in your organization as not every application should be patched automatically.

Associated Bulletins

ZSB-24025 | Zoom

ZSB-24022 | Zoom

Resources

Trending Articles & Security Reports

Resources

CyberWatch

September 18, 2024

Adobe Patched Potential Zero-Day in Reader

Adobe released a patch for a suspected zero-day vulnerability in Adobe Reader, identified as CVE-2024-41869. This vulnerability, a Use After Free (UAF) issue, can lead to arbitrary code execution, system crashes, or the return of unexpected values.

Find out more
September 16, 2024

Why We Need NIST's Post-Quantum Cryptography Standards

Last month, NIST published its first set of post-quantum cryptography (PQC) standards, setting a new benchmark for enterprises, government agencies, and vendors to withstand future cyberattacks from quantum computers. The time to start transitioning is now. Discover what’s at stake with CyberWatch.

Find out more
September 13, 2024

Patch Tuesday for September

Every second Tuesday of the month, Microsoft releases patches to their applications, services, and operating systems. Typically, these patches include a myriad of security fixes and this time around, for September of 2024, 79 different vulnerabilities have been addressed, including 4 zero-day vulnerabilities and 10 critical vulnerabilities.

Find out more