QID 377595
Date Published: 2022-09-20
QID 377595: Zoom Client for Meetings Local Privilege Escalation Vulnerability (ZSB-21005)
Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
CVE-2021-34409: It was discovered that the installation packages of the Zoom Client for Meetings for macOS (Standard and for IT Admin) installation before version 5.2.0 copy pre- and post- installation shell scripts to a user-writable directory. In the affected products listed below, a malicious actor with local access to a user's machine could use this flaw to potentially run arbitrary system commands in a higher privileged context during the installation process.
Affected Versions:
Zoom Client for Meetings for macOS before version 5.2.0
QID Detection Logic (Authenticated):
MacOS: This authenticated QID detects vulnerable Zoom Client prior to version 5.2.0
Successful exploitation of this vulnerability could allow an low privileged attacker to escalate to higher privileges.
CVEs related to QID 377595
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-21005 |
|