CVE-2024-27240: Rooms Input Validation Flaw (CVSS 7.8)

{ "CVE_ID": "CVE-2024-27240", "Severity_Rating": "High", "CVSS_Score": 7.8, "Description": "Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.", "EPSS_Estimation": { "Probability": 0.17, "Percentile": "7.1th" }, "Metrics": { "CVSS_Version": "3.1", "Vector_String": "AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" }, "Weakness_Enumeration": "CWE-20", "Affected_Software": [ { "Vendor": "Zoom", "Product": "Rooms", "Versions": "< 6.0.0" }, { "Vendor": "Zoom", "Product": "Workplace Desktop", "Versions": "< 6.0.0" }, { "Vendor": "Zoom", "Product": "Workplace Virtual Desktop Infrastructure", "Versions": "< 5.17.13" } ], "References": [ "https://www.zoom.com/en/trust/security-bulletin/zsb-24019" ], "Timeline": { "Published": "Jul 15, 2024", "Last_Modified": "Jun 17, 2026", "Status": "Analyzed" }, "FAQs": [ { "Question": "What is CVE-2024-27240?", "Answer": "Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access." }, { "Question": "How severe is CVE-2024-27240?", "Answer": "CVE-2024-27240 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days." }, { "Question": "How do I fix CVE-2024-27240?", "Answer": "Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected." } ], "Related_CVEs": [ { "CVE_ID": "CVE-2024-27235", "Description": "In plugin_extern_func of , there is a possible out of bounds…", "Severity": 5.5 }, { "CVE_ID": "CVE-2024-27236", "Description": "In aoc_unlocked_ioctl of aoc.c, there is a possible memory c…", "Severity": 8.4 }, { "CVE_ID": "CVE-2024-27237", "Description": "In wipe_ns_memory of nsmemwipe.c, there is a possible incorr…", "Severity": 5.5 }, { "CVE_ID": "CVE-2024-27238", "Description": "Race condition in the installer for some Zoom Apps and SDKs …", "Severity": 6.3 }, { "CVE_ID": "CVE-2024-27239", "Description": "Use after free in some Zoom Workplace Apps and SDKs may allo…", "Severity": 6.5 }, { "CVE_ID": "CVE-2024-27240", "Description": "SQL injection vulnerability in the CIGESv2 system, through /…", "Severity": 7.5 }, { "CVE_ID": "CVE-2024-27241", "Description": "Improper input validation in some Zoom Apps and SDKs may all…", "Severity": 7.5 }, { "CVE_ID": "CVE-2024-27242", "Description": "Cross site scripting in Zoom Desktop Client for Linux before…", "Severity": 6.8 }, { "CVE_ID": "CVE-2024-27243", "Description": "Buffer overflow in some Zoom Workplace Apps and SDK’s may al…", "Severity": 6.5 }, { "CVE_ID": "CVE-2024-27244", "Description": "Insufficient verification of data authenticity in the instal…", "Severity": 7.8 }, { "CVE_ID": "CVE-2024-27245", "Description": "Buffer overflow in some Zoom Workplace Apps and SDKs may all…", "Severity": 6.5 }, { "CVE_ID": "CVE-2024-27246", "Description": "Use after free in some Zoom Workplace Apps and SDKs may allo…", "Severity": 6.5 } ], "Source": "NVD / NIST" }