First published: Thu Nov 11 2021(Updated: )
In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering attacks.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34419 is considered a medium-severity vulnerability due to its potential for social engineering attacks.
To resolve CVE-2021-34419, users should update the Zoom Client for Meetings to version 5.1.0 or later.
CVE-2021-34419 can enable attackers to conduct social engineering attacks on meeting participants through HTML injection.
Only versions of Zoom Client for Meetings for Ubuntu Linux before 5.1.0 are affected by CVE-2021-34419.
CVE-2021-34419 is an HTML injection flaw that occurs during remote control requests while screen sharing in Zoom meetings.