CVE-2021-33907 is a critical vulnerability affecting Zoom Client for Meetings for Windows versions prior to 5.3.0. It stems from improper certificate validation during client updates, allowing for remote code execution with elevated privileges. With a CVSS score of 9.8, this vulnerability is highly severe, requiring no user interaction and having a low attack complexity. While no active exploitation, public exploits, or significant community discussion have been observed, the potential impact of this flaw is substantial.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.