CVE Feed

    Dashboard / CVE / CVE-2021-34423

    CVE-2021-34423

    A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom On-Premise Meeting Connector Controller before version 4.8.12.20211115, Zoom On-Premise Meeting Connector MMR before version 4.8.12.20211115, Zoom On-Premise Recording Connector before version 5.1.0.65.20211116, Zoom On-Premise Virtual Room Connector before version 4.4.7266.20211117, Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64. This can potentially allow a malicious actor to crash the service or application, or leverage this vulnerability to execute arbitrary code.

    Published:Nov 24, 2021
    Last Modified:Nov 21, 2024
    EPS:Nov 24, 2021
    EPSS Score:0.01599
    CVSS Score:9.8

    Affected Products

    Vendor
    Apple
    Product
    Iphone Os
    Vendor
    Apple
    Product
    Macos
    Vendor
    Google
    Product
    Android
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Microsoft
    Product
    Windows
    Vendor
    Zoom
    Product
    Android Meeting Sdk
    Vendor
    Zoom
    Product
    Android Video Sdk
    Vendor
    Zoom
    Product
    Controllers For Zoom Rooms
    Vendor
    Zoom
    Product
    Hybrid Mmr
    Vendor
    Zoom
    Product
    Hybrid Zproxy
    Vendor
    Zoom
    Product
    Iphone Os Meeting Sdk
    Vendor
    Zoom
    Product
    Iphone Os Video Sdk
    Vendor
    Zoom
    Product
    Macos Meeting Sdk
    Vendor
    Zoom
    Product
    Macos Video Sdk
    Vendor
    Zoom
    Product
    Meetings
    Vendor
    Zoom
    Product
    Meetings For Blackberry
    Vendor
    Zoom
    Product
    Meetings For Chrome Os
    Vendor
    Zoom
    Product
    Meetings For Intune
    Vendor
    Zoom
    Product
    Rooms For Conference Rooms
    Vendor
    Zoom
    Product
    Vdi Azure Virtual Desktop
    Vendor
    Zoom
    Product
    Vdi Citrix
    Vendor
    Zoom
    Product
    Vdi Vmware
    Vendor
    Zoom
    Product
    Vdi Windows Meeting Client
    Vendor
    Zoom
    Product
    Virtual Desktop Infrastructure
    Vendor
    Zoom
    Product
    Windows Meeting Sdk
    Vendor
    Zoom
    Product
    Windows Video Sdk
    Vendor
    Zoom
    Product
    Zoom On-premise Meeting Connector Controller
    Vendor
    Zoom
    Product
    Zoom On-premise Meeting Connector Mmr
    Vendor
    Zoom
    Product
    Zoom On-premise Recording Connector
    Vendor
    Zoom
    Product
    Zoom On-premise Virtual Room Connector
    Vendor
    Zoom
    Product
    Zoom On-premise Virtual Room Connector Load Balancer

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High