CVE-2021-34420

MEDIUM

Zoom Client for Meetings < 5.4.4 - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

Scores

CVSS v3 4.7
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Details

CWE
CWE-347
Status published
Products (1)
zoom/zoom_client_for_meetings < 5.4.4
Published Nov 11, 2021
Tracked Since Feb 18, 2026