First published: Thu Nov 11 2021(Updated: )
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34420 is classified as a high severity vulnerability due to improper file signature verification.
To fix CVE-2021-34420, upgrade to the Zoom Client for Meetings for Windows version 5.5.4 or later.
CVE-2021-34420 affects files with .msi, .ps1, and .bat extensions.
Any user of the Zoom Client for Meetings for Windows versions prior to 5.5.4 is impacted by CVE-2021-34420.
An attacker exploiting CVE-2021-34420 could install malicious software on a user's computer.