CVE Database
/

CVE-2021-34424

Back to search

CVE-2021-34424

Published: Nov 24, 2021

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom on-premise Meeting Connector before version 4.8.12.20211115, Zoom on-premise Meeting Connector MMR before version 4.8.12.20211115, Zoom on-premise Recording Connector before version 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector before version 4.4.7266.20211117, Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64 which potentially allowed for the exposure of the state of process memory. This issue could be used to potentially gain insight into arbitrary areas of the product's memory.

VendorProductVersions

Zoom Video Communications Inc

Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)

affected
unspecified - < 5.8.4

Zoom Video Communications Inc

Zoom Client for Meetings for Blackberry (for Android and iOS)

affected
unspecified - < 5.8.1

Zoom Video Communications Inc

Zoom Client for Meetings for intune (for Android and iOS)

affected
unspecified - < 5.8.4

Zoom Video Communications Inc

Zoom Client for Meetings for Chrome OS

affected
unspecified - < 5.0.1

Zoom Video Communications Inc

Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows)

affected
unspecified - < 5.8.3

Zoom Video Communications Inc

Controllers for Zoom Rooms (for Android, iOS, and Windows)

affected
unspecified - < 5.8.3

Zoom Video Communications Inc

Zoom VDI Windows Meeting Client

affected
unspecified - < 5.8.4

Zoom Video Communications Inc

Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64)

affected
unspecified - < 5.8.4.21112

Zoom Video Communications Inc

Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS)

affected
unspecified - < 5.8.4.21112

Zoom Video Communications Inc

Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS)

affected
unspecified - < 5.8.4.21112

Zoom Video Communications Inc

Zoom Meeting SDK for Android

affected
unspecified - < 5.7.6.1922

Zoom Video Communications Inc

Zoom Meeting SDK for iOS

affected
unspecified - < 5.7.6.1082

Zoom Video Communications Inc

Zoom Meeting SDK for macOS

affected
unspecified - < 5.7.6.1340

Zoom Video Communications Inc

Zoom Meeting SDK for Windows

affected
unspecified - < 5.7.6.1081

Zoom Video Communications Inc

Zoom Video SDK (for Android, iOS, macOS, and Windows)

affected
unspecified - < 1.1.2

Zoom Video Communications Inc

Zoom on-premise Meeting Connector

affected
unspecified - < 4.8.12.20211115

Zoom Video Communications Inc

Zoom on-premise Meeting Connector MMR

affected
unspecified - < 4.8.12.20211115

Zoom Video Communications Inc

Zoom on-premise Recording Connector

affected
unspecified - < 5.1.0.65.20211116

Zoom Video Communications Inc

Zoom on-premise Virtual Room Connector

affected
unspecified - < 4.4.7266.20211117

Zoom Video Communications Inc

Zoom on-premise Virtual Room Connector Load Balancer

affected
unspecified - < 2.5.5692.20211117

Zoom Video Communications Inc

Zoom Hybrid Zproxy

affected
unspecified - < 1.0.1058.20211116

Zoom Video Communications Inc

Zoom Hybrid MMR

affected
unspecified - < 4.6.20211116.131_x86-64

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now