CVE-2021-34420
MEDIUMZoom Client for Meetings < 5.4.4 - Improper Verification of Cryptographic Signature
Title source: llmDescription
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://explore.zoom.us/en/trust/security/security-bulletin
Third Party Advisory x_refsource_misc
https://medium.com/manomano-tech/a-red-team-operation-leveraging-a-zero-day-vulnerability-in-zoom-80f57fb0822e
Scores
CVSS v3
4.7
EPSS
0.0012
EPSS Percentile
30.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Details
CWE
CWE-347
Status
published
Products (1)
zoom/zoom_client_for_meetings
< 5.4.4
Published
Nov 11, 2021
Tracked Since
Feb 18, 2026