CVE Published: 27/09/2021 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: Zoom |
Vendor: n/a |
Product: Zoom Client for Meetings for Windows Status : PUBLISHED
CVE-2021-34408 Description
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.