PT-2021-20516 · Zoom · Zoom Client For Meetings+2
Published
2021-09-27
·
Updated
2022-10-06
·
CVE-2021-34409
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Zoom Client for Meetings for MacOS versions prior to 5.2.0
Zoom Client Plugin for Sharing iPhone/iPad versions prior to 5.2.0
Zoom Rooms for Conference versions prior to 5.1.0
Description:
A flaw was discovered in the installation packages of certain Zoom products, where pre- and post-installation shell scripts are copied to a user-writable directory. This could allow a malicious actor with local access to a user's machine to potentially run arbitrary system commands in a higher privileged context during the installation process, leading to privilege escalation to root.
Recommendations:
For Zoom Client for Meetings for MacOS versions prior to 5.2.0, update to version 5.2.0 or later to resolve the issue.
For Zoom Client Plugin for Sharing iPhone/iPad versions prior to 5.2.0, update to version 5.2.0 or later to resolve the issue.
For Zoom Rooms for Conference versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoom Client Plugin For Sharing
Zoom Client For Meetings
Zoom Rooms For Conference Room