{
  "CVE_ID": "CVE-2024-27240",
  "Severity_Rating": "High",
  "CVSS_Score": 7.8,
  "Description": "Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.",
  "EPSS_Estimation": {
    "Probability": 0.17,
    "Percentile": "7.1th"
  },
  "Metrics": {
    "CVSS_Version": "3.1",
    "Vector_String": "AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
  },
  "Weakness_Enumeration": "CWE-20",
  "Affected_Software": [
    { "Vendor": "Zoom", "Product": "Rooms", "Versions": "< 6.0.0" },
    { "Vendor": "Zoom", "Product": "Workplace Desktop", "Versions": "< 6.0.0" },
    { "Vendor": "Zoom", "Product": "Workplace Virtual Desktop Infrastructure", "Versions": "< 5.17.13" }
  ],
  "References": [
    "https://www.zoom.com/en/trust/security-bulletin/zsb-24019"
  ],
  "Timeline": {
    "Published": "Jul 15, 2024",
    "Last_Modified": "Jun 17, 2026",
    "Status": "Analyzed"
  },
  "FAQs": [
    {
      "Question": "What is CVE-2024-27240?",
      "Answer": "Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access."
    },
    {
      "Question": "How severe is CVE-2024-27240?",
      "Answer": "CVE-2024-27240 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days."
    },
    {
      "Question": "How do I fix CVE-2024-27240?",
      "Answer": "Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected."
    }
  ],
  "Related_CVEs": [
    { "CVE_ID": "CVE-2024-27235", "Description": "In plugin_extern_func of , there is a possible out of bounds…", "Severity": 5.5 },
    { "CVE_ID": "CVE-2024-27236", "Description": "In aoc_unlocked_ioctl of aoc.c, there is a possible memory c…", "Severity": 8.4 },
    { "CVE_ID": "CVE-2024-27237", "Description": "In wipe_ns_memory of nsmemwipe.c, there is a possible incorr…", "Severity": 5.5 },
    { "CVE_ID": "CVE-2024-27238", "Description": "Race condition in the installer for some Zoom Apps and SDKs …", "Severity": 6.3 },
    { "CVE_ID": "CVE-2024-27239", "Description": "Use after free in some Zoom Workplace Apps and SDKs may allo…", "Severity": 6.5 },
    { "CVE_ID": "CVE-2024-27240", "Description": "SQL injection vulnerability in the CIGESv2 system, through /…", "Severity": 7.5 },
    { "CVE_ID": "CVE-2024-27241", "Description": "Improper input validation in some Zoom Apps and SDKs may all…", "Severity": 7.5 },
    { "CVE_ID": "CVE-2024-27242", "Description": "Cross site scripting in Zoom Desktop Client for Linux before…", "Severity": 6.8 },
    { "CVE_ID": "CVE-2024-27243", "Description": "Buffer overflow in some Zoom Workplace Apps and SDK’s may al…", "Severity": 6.5 },
    { "CVE_ID": "CVE-2024-27244", "Description": "Insufficient verification of data authenticity in the instal…", "Severity": 7.8 },
    { "CVE_ID": "CVE-2024-27245", "Description": "Buffer overflow in some Zoom Workplace Apps and SDKs may all…", "Severity": 6.5 },
    { "CVE_ID": "CVE-2024-27246", "Description": "Use after free in some Zoom Workplace Apps and SDKs may allo…", "Severity": 6.5 }
  ],
  "Source": "NVD / NIST"
}
