PT-2021-7436 · Zoom · Zoom On-Premise Recording Connector+3

Jeremy Brown

·

Published

2021-11-09

·

Updated

2021-11-16

·

CVE-2021-34418

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Zoom On-Premise Meeting Connector versions prior to 4.6.239.20200613 Zoom On-Premise Meeting Connector MMR versions prior to 4.6.239.20200613 Zoom On-Premise Recording Connector versions prior to 3.8.42.20200905 Zoom On-Premise Virtual Room Connector versions prior to 4.4.6344.20200612 Zoom On-Premise Virtual Room Connector Load Balancer versions prior to 2.5.5492.20200616
Description The login routine of the web console fails to validate that a NULL byte was sent while authenticating, which could lead to a crash of the login service. This issue is related to a null pointer dereference, and its exploitation may allow an attacker to cause a denial of service.
Recommendations For Zoom On-Premise Meeting Connector versions prior to 4.6.239.20200613, update to version 4.6.239.20200613 or later. For Zoom On-Premise Meeting Connector MMR versions prior to 4.6.239.20200613, update to version 4.6.239.20200613 or later. For Zoom On-Premise Recording Connector versions prior to 3.8.42.20200905, update to version 3.8.42.20200905 or later. For Zoom On-Premise Virtual Room Connector versions prior to 4.4.6344.20200612, update to version 4.4.6344.20200612 or later. For Zoom On-Premise Virtual Room Connector Load Balancer versions prior to 2.5.5492.20200616, update to version 2.5.5492.20200616 or later.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06241
CVE-2021-34418

Affected Products

Zoom On-Premise Meeting Connector Mmr
Zoom On-Premise Recording Connector
Zoom On-Premise Virtual Room Connector
Zoom On-Premise Virtual Room Connector Load Balancer