Zoom Windows installation executable signature bypass
CVE-2021-34420

4.7MEDIUM

Key Information:

Vendor
Zoom
Vendor
CVE Published:
11 November 2021

Summary

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

Affected Version(s)

Zoom Client for Meetings for Windows < 5.5.4

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Laurent Delosieres of ManoMano
.