First published: Mon Sep 27 2021(Updated: )
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34412 is a vulnerability in the installation process of Zoom Client for Meetings for Windows before version 5.4.0, which can lead to a local privilege escalation.
CVE-2021-34412 can be exploited by launching Internet Explorer during the installation process of Zoom Client with elevated privileges.
CVE-2021-34412 has a severity value of 7.8 (High).
CVE-2021-34412 affects all versions of Zoom Client for Meetings for Windows before version 5.4.0.
To fix CVE-2021-34412, update your Zoom Client for Meetings for Windows to version 5.4.0 or newer.