Zoom Windows installation executable signature bypass
CVE-2021-34420
4.7MEDIUM
Key Information:
- Vendor
- Zoom
- Vendor
- CVE Published:
- 11 November 2021
Summary
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.
Affected Version(s)
Zoom Client for Meetings for Windows < 5.5.4
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Laurent Delosieres of ManoMano