QID 376046

Date Published: 2021-11-30

QID 376046: Zoom Client For Window Signature Bypass Vulnerability (ZSB-21016)

Zoom brings video conferencing, online meetings and group messaging into one easy-to-use application.

The Zoom Client for Meetings for Windows installer does not properly verify the signature of files with .msi, .ps1, and .bat extensions.

Affected Versions:
Zoom version prior to 5.5.4

This could lead to a malicious actor installing malicious software on a customer computer.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers can update to latest version here

    CVEs related to QID 376046

    Software Advisories
    Advisory ID Software Component Link
    ZSB-21016 Windows URL Logo zoom.us/download