CVE-2021-34423
Zoom 客户端和其他产品中的缓冲区溢出漏洞
- 已发布
- 2021年11月24日
- 已更新
- 2024年9月17日
- 分配 CNA
- Zoom
- 观察到的证据
- 2026年8月8日
初级CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H低 · 未来 30 天
- 百分位
- 87.9%
- 型号日期
- 2026年9月21日
EPSS 是统计估计,而不是确定性或影响衡量标准。将其与 CVSS、KEV 状态、暴露程度和您的环境相结合。
总结
在 Zoom Client for Meetings(适用于 Android、iOS、Linux、macOS 和 Windows)5.8.4 之前的版本、Zoom Client for Meetings for Blackberry(适用于 Android 和 iOS)5.8.1 之前的版本、Zoom Client for Meetings for intune(适用于 Android 和 iOS)5.8.4 之前的版本、Zoom Client for Meetings for Chrome OS 5.0.1 之前的版本、Zoom Rooms for Conference Room(适用于 Android、AndroidBali、macOS 和 Windows)5.8.3 之前的版本、Controllers for Zoom Rooms(适用于 Android、iOS 和 Windows)5.8.3 之前的版本、Zoom VDI Windows Meeting Client 5.8.4 之前的版本、Zoom VDI Azure Virtual Desktop Plugins(适用于 Windows x86 或 x64、IGEL x64、Ubuntu x64、HP ThinPro OS x64)5.8.4.21112 之前的版本、Zoom VDI Citrix Plugins(适用于 Windows x86 或 x64、Mac Universal Installer & Uninstaller、IGEL x64、eLux RP6 x64、HP ThinPro OS x64、Ubuntu x64、CentOS x 64、Dell ThinOS)5.8.4.21112 之前的版本、Zoom VDI VMware Plugins(适用于 Windows x86 或 x64、Mac Universal Installer & Uninstaller、IGEL x64、eLux RP6 x64、HP ThinPro OS x64、Ubuntu x64、CentOS x 64、Dell ThinOS)5.8.4.21112 之前的版本、Zoom Meeting SDK for Android 5.7.6.1922 之前的版本、Zoom Meeting SDK for iOS 5.7.6.1082 之前的版本、Zoom Meeting SDK for macOS 5.7.6.1340 之前的版本、Zoom Meeting SDK for Windows 5.7.6.1081 之前的版本、Zoom Video SDK(适用于 Android、iOS、macOS 和 Windows)1.1.2 之前的版本、Zoom On-Premise Meeting Connector Controller 4.8.12.20211115 之前的版本、Zoom On-Premise Meeting Connector MMR 4.8.12.20211115 之前的版本、Zoom On-Premise Recording Connector 5.1.0.65.20211116 之前的版本、Zoom On-Premise Virtual Room Connector 4.4.7266.20211117 之前的版本、Zoom On-Premise Virtual Room Connector Load Balancer 2.5.5692.20211117 之前的版本、Zoom Hybrid Zproxy 1.0.1058.20211116 之前的版本以及 Zoom Hybrid MMR 4.6.20211116.131_x86-64 之前的版本中发现了一个缓冲区溢出漏洞。这可能允许恶意行为者导致服务或应用程序崩溃,或利用此漏洞执行任意代码。
来源
2nuclei 扫描器,用于检测 proxyshell(CVE-2021-34473)漏洞
负责任的使用
仅在您拥有或有权测试的系统上使用漏洞信息。 Kitploit 链接到公共研究元数据,并且不存储漏洞代码或恶意负载。