First published: Mon Sep 27 2021(Updated: )
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33907.
The severity of CVE-2021-33907 is critical with a severity value of 9.8.
CVE-2021-33907 is a vulnerability in the Zoom Client for Meetings for Windows that allows remote code execution in an elevated privileged context due to improper validation of certificate information.
All versions of the Zoom Client for Meetings for Windows before 5.3.0 are affected by CVE-2021-33907.
To fix CVE-2021-33907, update the Zoom Client for Meetings for Windows to version 5.3.0 or later.