CVE-2024-45426 Details
Description
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
A vulnerability exists in some Zoom Workplace Apps due to incorrect ownership assignment, which may enable a privileged user to disclose information through network access. This issue affects multiple platforms, including Windows, Linux, iOS, and within the Zoom Rooms and VDI Client environments. The vulnerability arises from improper management of ownership rights, potentially allowing unauthorized information access.
Users are advised to update to the latest version of the Zoom Workplace App. The updated versions can be downloaded from the Zoom Download Center. For Zoom Rooms and Controllers, version 6.1.0 or later is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-24038/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-708 | Incorrect Ownership Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zoom meeting software development kit | < 6.1.0 |
CPE
Remediation
| |
| zoom rooms | < 6.1.0 |
CPE
Remediation
| |
| zoom rooms controller | < 6.1.0 |
CPE
Remediation
| |
| zoom workplace | < 6.1.0 |
CPE
Remediation
| |
| zoom workplace desktop | < 6.1.0 |
CPE
Remediation
| |
| zoom workplace virtual desktop infrastructure | < 6.1.10 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | Initial Analysis | [email protected] |
| Feb 25, 2025 | New CVE Received | [email protected] |