ZOOM Client是美国ZOOM公司的一款支持多种平台的视频会议客户端应用程序。 Zoom Client for Meetings 5.5.4之前版本的windows 安装程序存在数据伪造问题漏洞,该漏洞源于未正确验证扩展名为.msi、.ps1和.bat的文件的签名。攻击者可利用该漏洞在客户的计算机上安装恶意软件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Video Communications Inc | Zoom Client for Meetings for Windows | unspecified ~ 5.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-34417 | 7.9 HIGH | Authenticated remote command execution with root privileges via web console in MMR |
| CVE-2021-34422 | 7.2 HIGH | Path traversal of file names in Keybase Client for Windows |
| CVE-2021-34418 | 4.0 MEDIUM | Pre-auth Null pointer crash in on-premise web console |
| CVE-2021-34419 | 3.7 LOW | HTML injection in Zoom Linux client |
| CVE-2021-34421 | 3.7 LOW | Retained exploded messages in Keybase Clients for Android and iOS |
No comments yet