CVE-2021-34423
Pufferüberlauf im Zoom-Client und anderen Produkten
- Veröffentlicht
- 24.11.2021
- Aktualisiert
- 17.09.2024
- CNA zuweisen
- Zoom
- Beweise beobachtet
- 08.08.2026
Primäres CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNiedrig · nächste 30 Tage
- Perzentil
- 87,9 %
- Modelldatum
- 21.09.2026
EPSS ist eine statistische Schätzung, keine Gewissheit oder ein Maß für die Auswirkung. Kombinieren Sie es mit CVSS, KEV-Status, Belichtung und Ihrer Umgebung.
Zusammenfassung
Eine Pufferüberlauf-Schwachstelle wurde in Zoom Client for Meetings (für Android, iOS, Linux, macOS und Windows) vor Version 5.8.4, Zoom Client for Meetings for Blackberry (für Android und iOS) vor Version 5.8.1, Zoom Client for Meetings for intune (für Android und iOS) vor Version 5.8.4, Zoom Client for Meetings for Chrome OS vor Version 5.0.1, Zoom Rooms for Conference Room (für Android, AndroidBali, macOS und Windows) vor Version 5.8.3, Controllers for Zoom Rooms (für Android, iOS und Windows) vor Version 5.8.3, Zoom VDI Windows Meeting Client vor Version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (für Windows x86 oder x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) vor Version 5.8.4.21112, Zoom VDI Citrix Plugins (für Windows x86 oder x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) vor Version 5.8.4.21112, Zoom VDI VMware Plugins (für Windows x86 oder x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) vor Version 5.8.4.21112, Zoom Meeting SDK for Android vor Version 5.7.6.1922, Zoom Meeting SDK for iOS vor Version 5.7.6.1082, Zoom Meeting SDK for macOS vor Version 5.7.6.1340, Zoom Meeting SDK for Windows vor Version 5.7.6.1081, Zoom Video SDK (für Android, iOS, macOS und Windows) vor Version 1.1.2, Zoom On-Premise Meeting Connector Controller vor Version 4.8.12.20211115, Zoom On-Premise Meeting Connector MMR vor Version 4.8.12.20211115, Zoom On-Premise Recording Connector vor Version 5.1.0.65.20211116, Zoom On-Premise Virtual Room Connector vor Version 4.4.7266.20211117, Zoom On-Premise Virtual Room Connector Load Balancer vor Version 2.5.5692.20211117, Zoom Hybrid Zproxy vor Version 1.0.1058.20211116 und Zoom Hybrid MMR vor Version 4.6.20211116.131_x86-64 entdeckt. Dies kann es einem böswilligen Akteur potenziell ermöglichen, den Dienst oder die Anwendung zum Absturz zu bringen oder diese Schwachstelle auszunutzen, um beliebigen Code auszuführen.
Quellen
2Verantwortungsvoller Umgang
Verwenden Sie Schwachstelleninformationen nur auf Systemen, die Sie besitzen oder zu deren Testen Sie berechtigt sind. Kitploit verlinkt auf öffentliche Forschungsmetadaten und speichert keinen Exploit-Code oder bösartige Payloads.