The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable directory used and a non-user writable directory.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://explore.zoom.us/en/trust/security/security-bulletin/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Zoom
Published: 2021-09-27T13:55:35
Updated: 2024-08-04T00:12:50.000Z
Reserved: 2021-06-09T00:00:00
Link: CVE-2021-34408
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-09-27T14:15:08.083
Modified: 2024-11-21T06:10:20.380
Link: CVE-2021-34408
Redhat
No data.