CVE-2021-34409

HIGH

Zoom Meetings < 5.2.0 - Privilege Escalation via User-Writable Installation Scripts

Title source: llm
STIX 2.1

Description

It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 8.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (3)
zoom/meetings < 5.2.0
zoom/rooms < 5.1.0
zoom/screen_sharing < 5.2.0 (2 CPE variants)
Published Sep 27, 2021
Tracked Since Feb 18, 2026