First published: Thu Nov 11 2021(Updated: )
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Zoom On-premise Meeting Connector Controller | <4.6.365.20210703 | |
Zoom Zoom On-premise Meeting Connector Mmr | <4.6.365.20210703 | |
Zoom Zoom On-premise Recording Connector | <3.8.45.20210703 | |
Zoom Zoom On-premise Virtual Room Connector | <4.4.6868.20210703 | |
Zoom Zoom On-premise Virtual Room Connector Load Balancer | <2.5.5496.20210703 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34417 is a vulnerability that affects the network proxy page on the web portal for multiple Zoom On-Premise products.
CVE-2021-34417 has a severity rating of critical (7.2).
Zoom On-Premise Meeting Connector Controller versions before 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR versions before 4.6.365.20210703, Zoom On-Premise Recording Connector versions before 3.8.45.20210703, Zoom On-Premise Virtual Room Connector versions before 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer versions before 2.5.5496.20210703 are affected by CVE-2021-34417.
To fix CVE-2021-34417, you should update your Zoom On-Premise Meeting Connector Controller, Zoom On-Premise Meeting Connector MMR, Zoom On-Premise Recording Connector, Zoom On-Premise Virtual Room Connector, and Zoom On-Premise Virtual Room Connector Load Balancer to versions 4.6.365.20210703, 4.6.365.20210703, 3.8.45.20210703, 4.4.6868.20210703, and 2.5.5496.20210703 respectively.
For more information about CVE-2021-34417, you can visit the Zoom security bulletin at https://explore.zoom.us/en/trust/security/security-bulletin.