CVE-2024-42441

Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*

History

02 Oct 2025, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 6.2
CWE CWE-269 CWE-266
Summary (en) Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. (en) Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.

28 Aug 2024, 23:58

Type Values Removed Values Added
References () https://www.zoom.com/en/trust/security-bulletin/zsb-24034 - () https://www.zoom.com/en/trust/security-bulletin/zsb-24034 - Vendor Advisory
Summary
  • (es) La gestión inadecuada de privilegios en el instalador de la aplicación de escritorio Zoom Workplace para macOS, Zoom Meeting SDK para macOS y Zoom Rooms Client para macOS anteriores a 6.1.5 puede permitir que un usuario privilegiado realice una escalada de privilegios a través del acceso local.
CPE cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
First Time Zoom rooms
Zoom workplace Desktop
Zoom
Zoom meeting Software Development Kit
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 6.7
CWE NVD-CWE-noinfo

14 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 17:15

Updated : 2025-10-02 21:16


NVD link : CVE-2024-42441

Mitre link : CVE-2024-42441

CVE.ORG link : CVE-2024-42441


JSON object : View

Products Affected

zoom

  • meeting_software_development_kit
  • rooms
  • workplace_desktop
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo