QID 376967

Date Published: 2022-09-05

QID 376967: Zoom Client for Meetings Remote Code Execution (RCE) Vulnerability (ZSB-21003)

Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.

The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client.

Affected Versions:
Zoom Client for Meetings for Windows prior to version 5.3.0

QID Detection Logic:
This authenticated QID detects vulnerable Zoom Client for Windows prior to version 5.3.0

Successful exploitation of this vulnerability may allow a privileged attacker to execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Zoom Client for Meetings for Windows version 5.3.0 or later to remediate these vulnerabilities.

    CVEs related to QID 376967

    Software Advisories
    Advisory ID Software Component Link
    ZSB-21003 URL Logo explore.zoom.us/en/trust/security/security-bulletin/