PT-2021-7429 · Zoom · Zoom On-Premise Recording Connector+4

Jeremy Brown

·

Published

2021-06-09

·

Updated

2021-11-16

·

CVE-2021-34417

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoom On-Premise Meeting Connector Controller versions prior to 4.6.365.20210703 Zoom On-Premise Meeting Connector MMR versions prior to 4.6.365.20210703 Zoom On-Premise Recording Connector versions prior to 3.8.45.20210703 Zoom On-Premise Virtual Room Connector versions prior to 4.4.6868.20210703 Zoom On-Premise Virtual Room Connector Load Balancer versions prior to 2.5.5496.20210703
Description The issue is related to insufficient input validation, which could allow a remote attacker to execute arbitrary code. Specifically, the network proxy page on the web portal for certain Zoom products fails to validate input sent in requests to set the network proxy password, potentially leading to remote command injection by a web portal administrator.
Recommendations For Zoom On-Premise Meeting Connector Controller versions prior to 4.6.365.20210703, update to version 4.6.365.20210703 or later. For Zoom On-Premise Meeting Connector MMR versions prior to 4.6.365.20210703, update to version 4.6.365.20210703 or later. For Zoom On-Premise Recording Connector versions prior to 3.8.45.20210703, update to version 3.8.45.20210703 or later. For Zoom On-Premise Virtual Room Connector versions prior to 4.4.6868.20210703, update to version 4.4.6868.20210703 or later. For Zoom On-Premise Virtual Room Connector Load Balancer versions prior to 2.5.5496.20210703, update to version 2.5.5496.20210703 or later. As a temporary workaround, consider restricting access to the network proxy page on the web portal to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06165
CVE-2021-34417

Affected Products

Zoom On-Premise Meeting Connector Controller
Zoom On-Premise Meeting Connector Mmr
Zoom On-Premise Recording Connector
Zoom On-Premise Virtual Room Connector
Zoom On-Premise Virtual Room Connector Load Balancer