CVE-2021-33907: Critical severity zoom client for meetings vulnerability
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Zoom Client for Meetings for Windows vulnerability?
The vulnerability ID is CVE-2021-33907.
What is the severity of CVE-2021-33907?
The severity of CVE-2021-33907 is critical with a severity value of 9.8.
What is the description of CVE-2021-33907?
CVE-2021-33907 is a vulnerability in the Zoom Client for Meetings for Windows that allows remote code execution in an elevated privileged context due to improper validation of certificate information.
Which version of the Zoom Client for Meetings for Windows is affected by CVE-2021-33907?
All versions of the Zoom Client for Meetings for Windows before 5.3.0 are affected by CVE-2021-33907.
How do I fix CVE-2021-33907?
To fix CVE-2021-33907, update the Zoom Client for Meetings for Windows to version 5.3.0 or later.