CVE-2021-34408: High severity zoom client for meetings vulnerability
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34408?
CVE-2021-34408 is a vulnerability in the Zoom Client for Meetings for Windows in all versions before version 5.3.2 that allows log files to be written to a user writable directory as a privileged user, potentially enabling privilege escalation.
What is the severity of CVE-2021-34408?
CVE-2021-34408 has a severity rating of 7.8 (high).
How does CVE-2021-34408 impact the Zoom Client for Meetings for Windows?
CVE-2021-34408 allows log files to be written to a user writable directory during the installation or update of the Zoom Client for Meetings for Windows, potentially leading to privilege escalation.
How can I fix CVE-2021-34408?
To fix CVE-2021-34408, update the Zoom Client for Meetings for Windows to version 5.3.2 or later.
Where can I find more information about CVE-2021-34408?
You can find more information about CVE-2021-34408 in the Zoom Client for Meetings security bulletin: [link](https://explore.zoom.us/en/trust/security/security-bulletin/)