Description
The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.
Published: 2021-09-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-21066 The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2024-08-04T00:12:50.000Z

Reserved: 2021-06-09T00:00:00.000Z

Link: CVE-2021-34408

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-27T14:15:08.083

Modified: 2024-11-21T06:10:20.380

Link: CVE-2021-34408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses