CVE-2021-33907
9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.96% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-295 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-09-27 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| zoom | meetings |
References
→ the Explorer · watch your stack · NVD