CVE-2021-34412: High severity zoom client for meetings vulnerability
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34412?
CVE-2021-34412 is a vulnerability in the installation process of Zoom Client for Meetings for Windows before version 5.4.0, which can lead to a local privilege escalation.
How can CVE-2021-34412 be exploited?
CVE-2021-34412 can be exploited by launching Internet Explorer during the installation process of Zoom Client with elevated privileges.
What is the severity of CVE-2021-34412?
CVE-2021-34412 has a severity value of 7.8 (High).
What is the affected software version of CVE-2021-34412?
CVE-2021-34412 affects all versions of Zoom Client for Meetings for Windows before version 5.4.0.
How can I fix CVE-2021-34412?
To fix CVE-2021-34412, update your Zoom Client for Meetings for Windows to version 5.4.0 or newer.