CVE-2021-34409 is a local privilege escalation vulnerability affecting Zoom Client for Meetings for macOS (Standard and IT Admin), Zoom Client Plugin for Sharing iPhone/iPad, and Zoom Rooms for Conference, all prior to specific versions. A local attacker could exploit this flaw during installation by manipulating shell scripts copied to a user-writable directory, allowing them to execute arbitrary commands with elevated privileges. Rated High severity (CVSS 7.8), it carries a significant risk of impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.2.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:* | ||
< 5.1.0CPE matchmatch criteria | cpe:2.3:a:zoom:rooms:*:*:*:*:*:*:*:* | ||
< 5.2.0CPE matchmatch criteria | cpe:2.3:a:zoom:screen_sharing:*:*:*:*:*:ipados:*:* | ||
< 5.2.0CPE matchmatch criteria | cpe:2.3:a:zoom:screen_sharing:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.