CVE-2024-42441

Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*

History

02 Oct 2025, 21:16

Type Values Removed Values Added
Summary (en) Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access. (en) Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 6.2
CWE CWE-269 CWE-266

28 Aug 2024, 23:58

Type Values Removed Values Added
First Time Zoom meeting Software Development Kit
Zoom
Zoom workplace Desktop
Zoom rooms
CWE NVD-CWE-noinfo
Summary
  • (es) La gestión inadecuada de privilegios en el instalador de la aplicación de escritorio Zoom Workplace para macOS, Zoom Meeting SDK para macOS y Zoom Rooms Client para macOS anteriores a 6.1.5 puede permitir que un usuario privilegiado realice una escalada de privilegios a través del acceso local.
References () https://www.zoom.com/en/trust/security-bulletin/zsb-24034 - () https://www.zoom.com/en/trust/security-bulletin/zsb-24034 - Vendor Advisory
CPE cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:*
cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:*
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 6.7

14 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 17:15

Updated : 2025-10-02 21:16


NVD link : CVE-2024-42441

Mitre link : CVE-2024-42441

CVE.ORG link : CVE-2024-42441


JSON object : View

Products Affected

zoom

  • rooms
  • meeting_software_development_kit
  • workplace_desktop
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo