CVE-2021-34420 Vulnerability Details

  /     /     /  

CVE-2021-34420 Metadata Quick Info

CVE Published: 11/11/2021 | CVE Updated: 16/09/2024 | CVE Year: 2021
Source: Zoom | Vendor: Zoom Video Communications Inc | Product: Zoom Client for Meetings for Windows
Status : PUBLISHED

CVE-2021-34420 Description

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.

Metrics

CVSS Version: 3.1 | Base Score: 4.7 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper Verification of Cryptographic Signature
Source: Zoom Video Communications Inc

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).