First published: Mon Sep 27 2021(Updated: )
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34408 is a vulnerability in the Zoom Client for Meetings for Windows in all versions before version 5.3.2 that allows log files to be written to a user writable directory as a privileged user, potentially enabling privilege escalation.
CVE-2021-34408 has a severity rating of 7.8 (high).
CVE-2021-34408 allows log files to be written to a user writable directory during the installation or update of the Zoom Client for Meetings for Windows, potentially leading to privilege escalation.
To fix CVE-2021-34408, update the Zoom Client for Meetings for Windows to version 5.3.2 or later.
You can find more information about CVE-2021-34408 in the Zoom Client for Meetings security bulletin: [link](https://explore.zoom.us/en/trust/security/security-bulletin/)