CVE-2024-27238: Zoom Meeting Software Development Kit
Medium severity, CVSS 6.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege escalation via local access.
Affected products
- Zoom Meeting Software Development Kit: before 6.0.0 (fixed in 6.0.0)
- Zoom Rooms: before 6.0.0 (fixed in 6.0.0)
- Zoom Workplace Desktop: before 6.0.0 (fixed in 6.0.0)
Published 2024-07-15. Last modified 2026-06-17.