logo

Zoom patches critical privilege elevation flaw in Windows apps

ID: 892f2715-0246-510c-9490-a50d6097ed4b

STIX ID: report--892f2715-0246-510c-9490-a50d6097ed4b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Zoom disclosed a critical improper input validation vulnerability (CVE-2024-24691, CVSS 9.6) affecting Zoom Desktop/VDI/Rooms clients and the Meeting SDK for Windows that can allow unauthenticated privilege escalation requiring user interaction; multiple related vulnerabilities were also fixed in the latest Windows releases and users are advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.