QID 376621
Date Published: 2022-05-23
QID 376621: Zoom VDI Local privilege escalation Vulnerability (ZSB-22004)
Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
CVE-2021-34424: Process memory exposure in Zoom Client and other products
CVE-2021-34423:Buffer overflow in Zoom Client and other products
Affected Versions:
Zoom VDI Windows Meeting Clients prior to version 5.9.6
QID Detection Logic:
This authenticated QID detects vulnerable Zoom VDI Windows Meeting Clients prior to version 5.9.6 on Windows
Successful exploit may cause integrity or availability issues
Solution
Customers are advised to upgrade to Zoom VDI Windows Meeting Clients 5.9.6 or later to remediate these vulnerabilities.
Vendor References
- ZSB-22004 Zoom VDI Windows Meeting Clients -
explore.zoom.us/en/trust/security/security-bulletin/
CVEs related to QID 376621
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-22004 |
|