CVE-2021-34420: Zoom Windows installation executable signature bypass
Published Nov 11, 2021
·Updated
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.
Affected Software
1 affected component
Zoom Zoom Client For Meetings Windows<5.4.4
Event History
Nov 11, 2021
CVE Published
via MITRE·10:59 PM
Data Sourced
via MITRE·10:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-34420?
CVE-2021-34420 is classified as a high severity vulnerability due to improper file signature verification.
2
How do I fix CVE-2021-34420?
To fix CVE-2021-34420, upgrade to the Zoom Client for Meetings for Windows version 5.5.4 or later.
3
What types of files are affected by CVE-2021-34420?
CVE-2021-34420 affects files with .msi, .ps1, and .bat extensions.
4
Who is impacted by CVE-2021-34420?
Any user of the Zoom Client for Meetings for Windows versions prior to 5.5.4 is impacted by CVE-2021-34420.
5
What can an attacker do with CVE-2021-34420?
An attacker exploiting CVE-2021-34420 could install malicious software on a user's computer.