Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-24040/ |     | 
History
                    Tue, 04 Mar 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Zoom Zoom meeting Software Development Kit Zoom rooms Zoom video Software Development Kit Zoom workplace Desktop | |
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:video_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:* | |
| Vendors & Products | Zoom Zoom meeting Software Development Kit Zoom rooms Zoom video Software Development Kit Zoom workplace Desktop | 
Tue, 25 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 25 Feb 2025 20:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Title | Zoom Apps for macOS - Symbolic Link Following | |
| Weaknesses | CWE-61 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Zoom
Published: 2025-02-25T19:52:25.471Z
Updated: 2025-02-25T20:07:09.959Z
Reserved: 2024-08-28T21:50:25.332Z
Link: CVE-2024-45418
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-02-25T20:07:06.495Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-02-25T20:15:35.223
Modified: 2025-03-04T17:22:39.620
Link: CVE-2024-45418
 Redhat
                        Redhat
                    No data.