PT-2021-20523 · Zoom · Zoom On-Premise Meeting Connector Mmr+3

Egor Dimitrenko

·

Published

2021-09-27

·

Updated

2021-11-10

·

CVE-2021-34416

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zoom on-premise Meeting Connector versions prior to 4.6.360.20210325 Zoom on-premise Meeting Connector MMR versions prior to 4.6.360.20210325 Zoom on-premise Recording Connector versions prior to 3.8.44.20210326 Zoom on-premise Virtual Room Connector versions prior to 4.4.6752.20210326 Zoom on-premise Virtual Room Connector Load Balancer versions prior to 2.5.5495.20210326
Description: The network address administrative settings web portal for the Zoom on-premise products fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.
Recommendations: For Zoom on-premise Meeting Connector versions prior to 4.6.360.20210325, update to version 4.6.360.20210325 or later. For Zoom on-premise Meeting Connector MMR versions prior to 4.6.360.20210325, update to version 4.6.360.20210325 or later. For Zoom on-premise Recording Connector versions prior to 3.8.44.20210326, update to version 3.8.44.20210326 or later. For Zoom on-premise Virtual Room Connector versions prior to 4.4.6752.20210326, update to version 4.4.6752.20210326 or later. For Zoom on-premise Virtual Room Connector Load Balancer versions prior to 2.5.5495.20210326, update to version 2.5.5495.20210326 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34416

Affected Products

Zoom On-Premise Meeting Connector Mmr
Zoom On-Premise Recording Connector
Zoom On-Premise Virtual Room Connector
Zoom On-Premise Virtual Room Connector Load Balancer