peter bassill · operator
$ cve CVE-2021-33907 JSON

CVE-2021-33907

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.96% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-295
On CISA KEVno
Public exploitnone known
Published2021-09-27
Last modified2026-06-17

Affected (1)

VendorProduct
zoommeetings

References

→ the Explorer  ·  watch your stack  ·  NVD