CVE-2021-34418: Pre-auth Null pointer crash in on-premise web console
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616 fails to validate that a NULL byte was sent while authenticating. This could lead to a crash of the login service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Zoom On-Premise Meeting Connector issue?
The vulnerability ID for this Zoom On-Premise Meeting Connector issue is CVE-2021-34418.
What is the severity of CVE-2021-34418?
The severity of CVE-2021-34418 is medium with a CVSS score of 5.3.
Which software versions are affected by CVE-2021-34418?
The affected software versions are Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42.20200905, Zoom On-Premise Virtual Room Connector before version 4.4.6344.20200612, and Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5492.20200616.
How can I fix the Zoom On-Premise Meeting Connector vulnerability (CVE-2021-34418)?
To fix the vulnerability, you should update your Zoom On-Premise Meeting Connector to version 4.6.239.20200613 or higher.
Where can I find more information about CVE-2021-34418?
You can find more information about CVE-2021-34418 in the Zoom security bulletin at https://explore.zoom.us/en/trust/security/security-bulletin.