CVE-2021-34411
7.8HIGH
Key Information:
- Vendor
- Zoom
- Vendor
- CVE Published:
- 27 September 2021
Summary
During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to launch Internet Explorer with elevated privileges. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.
Affected Version(s)
Zoom Rooms for Conference Room for Windows All versions before 5.3.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved