First published: Mon Sep 27 2021(Updated: )
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting Connector | <4.6.358.20210205 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34415 is rated as a high severity vulnerability due to potential resource exhaustion and system crash.
To remediate CVE-2021-34415, upgrade to Zoom On-Premise Meeting Connector Controller version 4.6.358.20210205 or later.
CVE-2021-34415 can lead to a denial of service attack, resulting in resource exhaustion and inability to process incoming requests.
CVE-2021-34415 affects all versions of Zoom On-Premise Meeting Connector Controller prior to version 4.6.358.20210205.
Currently, the recommended solution for CVE-2021-34415 is to upgrade the vulnerable software to a secure version.