Security readout for executives and security teams
Plain-English summary
Keybase for Windows versions before 5.7.0 could mishandle a malicious filename in shared folders. In the wrong sharing setup, this could make a victim’s machine run an unintended application. The concern is highest where Keybase public or team folder sharing was used on Windows endpoints.
Executive priority
Prioritize remediation where Keybase for Windows was deployed, especially on systems using shared folders. The vulnerability has credible high-severity impact, but the provided evidence does not show known active exploitation.
Technical view
The flaw is a path traversal issue in filename checks for files uploaded to Keybase team folders on Windows. A crafted filename could lead to unintended application execution. The CVE lists potential remote code execution through public folder sharing. CVSS 3.1 is 7.2 with network attack vector, low complexity, and changed scope.
Likely exposure
Exposure is limited to Keybase Client for Windows before version 5.7.0. Organizations that did not deploy Keybase, only used non-Windows clients, or upgraded beyond 5.7.0 are less likely to be affected based on the provided sources.
Exploitation context
The provided sources do not report active exploitation, and this CVE is not marked KEV. The described scenario requires a malicious uploaded filename in a shared folder; public folder sharing could broaden impact to remote code execution.
Researcher notes
The source bundle names no CWE and gives limited implementation detail. Validate exposure by version and feature use rather than by exploit testing. Avoid assuming non-Windows impact or specific file paths because those details are not present in the sources.
Mitigation direction
- Upgrade Keybase Client for Windows to version 5.7.0 or later.
- Review Zoom or Keybase security guidance for any additional vendor instructions.
- Limit use of public folder sharing where legacy clients may remain.
- Prioritize remediation on Windows endpoints using Keybase team folders.
Validation and detection
- Inventory endpoints with Keybase Client for Windows installed.
- Confirm installed Keybase versions are 5.7.0 or later.
- Identify business units using Keybase team or public folder sharing.
- Review endpoint telemetry for unexpected application launches associated with Keybase activity.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupFile access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-34422 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.2 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N3.92.7Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.2HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://explore.zoom.us/en/trust/security/security-bulletinCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
