CVE-2021-34417: Authenticated remote command execution with root privileges via web console in MMR
The network proxy page on the web portal for the Zoom On-Premise Meeting Connector Controller before version 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR before version 4.6.365.20210703, Zoom On-Premise Recording Connector before version 3.8.45.20210703, Zoom On-Premise Virtual Room Connector before version 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5496.20210703 fails to validate input sent in requests to set the network proxy password. This could lead to remote command injection by a web portal administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34417?
CVE-2021-34417 is a vulnerability that affects the network proxy page on the web portal for multiple Zoom On-Premise products.
What is the severity of CVE-2021-34417?
CVE-2021-34417 has a severity rating of critical (7.2).
Which software versions are affected by CVE-2021-34417?
Zoom On-Premise Meeting Connector Controller versions before 4.6.365.20210703, Zoom On-Premise Meeting Connector MMR versions before 4.6.365.20210703, Zoom On-Premise Recording Connector versions before 3.8.45.20210703, Zoom On-Premise Virtual Room Connector versions before 4.4.6868.20210703, and Zoom On-Premise Virtual Room Connector Load Balancer versions before 2.5.5496.20210703 are affected by CVE-2021-34417.
How can I fix CVE-2021-34417?
To fix CVE-2021-34417, you should update your Zoom On-Premise Meeting Connector Controller, Zoom On-Premise Meeting Connector MMR, Zoom On-Premise Recording Connector, Zoom On-Premise Virtual Room Connector, and Zoom On-Premise Virtual Room Connector Load Balancer to versions 4.6.365.20210703, 4.6.365.20210703, 3.8.45.20210703, 4.4.6868.20210703, and 2.5.5496.20210703 respectively.
Where can I find more information about CVE-2021-34417?
For more information about CVE-2021-34417, you can visit the Zoom security bulletin at https://explore.zoom.us/en/trust/security/security-bulletin.