CVE-2021-34409

HIGH

Zoom Meetings < 5.2.0 - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (3)
zoom/meetings < 5.2.0
zoom/rooms < 5.1.0
zoom/screen_sharing < 5.2.0 (2 CPE variants)
Published Sep 27, 2021
Tracked Since Feb 18, 2026