Vulnerability Report

Two High Severity Bugs Fixed in Recent Zoom Update

By

Matthew Fagan, Vulnerability Management Patch Analyst

By

Access Point Consulting

Summary

On 08/13/2024, Zoom issued security advisories urging users to patch two high severity vulnerabilities: CVE-2024-39818 (CVSSv3: 7.5), an information disclosure vulnerability that allows an authenticated user to perform information disclosure through network access and CVE-2024-39825 (CVSSv3: 8.5), a buffer overflow that allows an authenticated user to conduct an escalation of privilege using network access. The affected applications are Zoom Workplace Desktop App, Zoom Workplace VDI Client, Zoom Workplace App for Android and iOS, and Zoom Rooms Application for Windows, Mac, and iPad.

Impact

Only attackers authenticated to one of the affected Zoom applications could exploit these vulnerabilities, but if exploited, the vulnerabilities would enable an attacker to perform information disclosure and/or privilege escalation on the affected system. No evidence exists indicating the bugs were exploited or that proof-of-concept code is publicly available.

Affected Applications

CVE-2024-39818

  • Zoom Workplace App for iOS before version 6.0.10
  • Zoom Workplace Desktop App for Linux before version 6.0.10
  • Zoom Workplace Desktop App for Windows before version 6.0.10
  • Zoom Workplace Desktop App for macOS before version 6.0.10
  • Zoom Workplace VDI Client for Windows before version 5.17.13
  • Zoom Meeting SDK for Windows before version 6.0.10
  • Zoom Meeting SDK for iOS before version 6.0.10
  • Zoom Meeting SDK for Android before version 6.0.10
  • Zoom Meeting SDK for macOS before version 6.0.10
  • Zoom Meeting SDK for Linux before version 6.0.10

CVE-2024-39825

  • Zoom Workplace Desktop App for Linux before version 6.0.0
  • Zoom Workplace Desktop App for Windows before version 6.0.0
  • Zoom Workplace Desktop App for macOS before version 6.0.0
  • Zoom Workplace VDI Client for Windows before version 5.17.13
  • Zoom Workplace App for iOS before version 6.0.0
  • Zoom Workplace App for Android before version 6.0.0
  • Zoom Rooms App for Windows before version 6.0.0
  • Zoom Rooms App for Mac before version 6.0.0
  • Zoom Rooms App for iPad before version 6.0.0

Remediation

Applying the latest updates as advised by the vendor is the remediation method. Zoom also has auto-update features in place which could be enabled to keep these applications up-to-date

Recommendations

Patch: We advise you to update the affected application(s) to the latest version at a normal priority. These vulnerabilities are not very high risk and can be mitigated through multifactor authentication.

Auto-update: It is always advised to implement automation to help with vulnerability remediation. In this case, setting up auto updating for these applications will assist in expediting any type of patch these applications would experience.  This should be discussed with leadership in your organization as not every application should be patched automatically.

Associated Bulletins

ZSB-24025 | Zoom

ZSB-24022 | Zoom

Resources

Latest Resources

Resources

CyberWatch

April 2, 2025

Scott "Monty" Montgomery (Island) | Navigating CMMC compliance for organizations of every size

Scott Montgomery, known as Monty, joined the CyberWatch Expert Series podcast to discuss his extensive background in cybersecurity, particularly in building and designing network security tools for high-assurance environments like the Department of Defense (DoD) and the intelligence community. His experience includes significant tenure at McAfee (now Trellix), which led him to his current role at Island, where he focuses on innovative approaches to cybersecurity compliance.

Find out more
March 19, 2025

Michael Sviben (DomainGuard) | Defending against phishing and building proactive security awareness

Cybersecurity threats evolve rapidly, and one tactic consistently rises above the rest: phishing. In this episode of CyberWatch, Michael Sviben, co-founder of DomainGuard, discusses why phishing remains so effective, how businesses and individuals become targets, and what you can do to stay vigilant.

Find out more
March 5, 2025

David Habib (Brightspot) | Building a culture of cybersecurity awareness

Cybersecurity awareness is often reduced to check-the-box training, but David Habib, CIO at Brightspot, argues that real security awareness isn’t about formal programs—it’s about making security part of a company’s culture. In this episode, he shares practical insights on how organizations can move beyond stale training sessions to create an engaged and security-conscious workforce.

Find out more