PT-2021-20516 · Zoom · Zoom Client For Meetings+2

Published

2021-09-27

·

Updated

2022-10-06

·

CVE-2021-34409

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zoom Client for Meetings for MacOS versions prior to 5.2.0 Zoom Client Plugin for Sharing iPhone/iPad versions prior to 5.2.0 Zoom Rooms for Conference versions prior to 5.1.0
Description: A flaw was discovered in the installation packages of certain Zoom products, where pre- and post-installation shell scripts are copied to a user-writable directory. This could allow a malicious actor with local access to a user's machine to potentially run arbitrary system commands in a higher privileged context during the installation process, leading to privilege escalation to root.
Recommendations: For Zoom Client for Meetings for MacOS versions prior to 5.2.0, update to version 5.2.0 or later to resolve the issue. For Zoom Client Plugin for Sharing iPhone/iPad versions prior to 5.2.0, update to version 5.2.0 or later to resolve the issue. For Zoom Rooms for Conference versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34409

Affected Products

Zoom Client Plugin For Sharing
Zoom Client For Meetings
Zoom Rooms For Conference Room