QID 376117

Date Published: 2021-12-01

QID 376117: Zoom Client Multiple Vulnerabilities

Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.

CVE-2021-34424: Process memory exposure in Zoom Client and other products
CVE-2021-34423:Buffer overflow in Zoom Client and other products

Affected Versions:
Zoom Client for Meetings macOS and Windows before version 5.8.4

QID Detection Logic:
This authenticated QID detects vulnerable Zoom client versions by checking if they are lesser than 5.8.4 on Windows and on Mac OS.

allow a malicious actor to crash the service or application, or leverage this vulnerability to execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Zoom Client 5.8.4 on Windows and on Mac OS or later to remediate these vulnerabilities.

    CVEs related to QID 376117

    Software Advisories
    Advisory ID Software Component Link
    ZSB-21019 URL Logo explore.zoom.us/en/trust/security/security-bulletin/
    ZSB-21020 URL Logo explore.zoom.us/en/trust/security/security-bulletin/