Fiche vulnérabilité
CVE-2021-34412 : faille élevée Zoom Client for Meetings for Windows (CVSS 7.8)
Description
During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege escalation.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 27 sept. 2021
- Dernière mise à jour
- 4 août 2024
Produits concernés
- Zoom Client for Meetings for Windows