Zoom Windows installation executable signature bypass
- ZSB-21016
- CVE-2021-34420
- Medium
- 4.7
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s computer.
Zoom addressed this issue in the 5.5.4 Zoom Client for Meetings for Windows release. Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.
- All Zoom Client for Meetings for Windows before version 5.5.4
Reported by Laurent Delosieres of ManoMano
| Revision | Date | Description |
|---|---|---|
| 1.0 | 11/09/2021 | Initial Publication |