# CVE-2024-24691

## Summary

- **CVE ID:** CVE-2024-24691
- **Severity:** CRITICAL
- **CVSS Score:** 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-176
- **Published:** Feb 14, 2024
- **Last Modified:** Mar 13, 2026

## Description

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

## Affected Products

- Zoom Video Communications, Inc. — Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows (see references)

## References

- [CNA](https://www.zoom.com/en/trust/security-bulletin/ZSB-24008/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.70%
- **EPSS Percentile:** 75.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._