CVE-2021-34424
Process memory exposure in Zoom Client and other products
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom on-premise Meeting Connector before version 4.8.12.20211115, Zoom on-premise Meeting Connector MMR before version 4.8.12.20211115, Zoom on-premise Recording Connector before version 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector before version 4.4.7266.20211117, Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64 which potentially allowed for the exposure of the state of process memory. This issue could be used to potentially gain insight into arbitrary areas of the product's memory.
Se ha detectado una vulnerabilidad en Zoom Client for Meetings (para Android, iOS, Linux, macOS y Windows) antes de la versión 5.8.4, Zoom Client for Meetings for Blackberry (para Android e iOS) antes de la versión 5.8.1, Zoom Client for Meetings for intune (para Android e iOS) antes de la versión 5.8.4, Zoom Client for Meetings for Chrome OS antes de la versión 5.0.1, Zoom Rooms for Conference Room (para Android, AndroidBali, macOS y Windows) antes de la versión 5.8. 3, Controllers for Zoom Rooms (para Android, iOS y Windows) antes de la versión 5.8.3, Zoom VDI Windows Meeting Client antes de la versión 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (para Windows x86 o x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) antes de la versión 5. 8.4.21112, Zoom VDI Citrix Plugins (para Windows x86 o x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) antes de la versión 5.8.4. 21112, Zoom VDI VMware Plugins (para Windows x86 o x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) antes de la versión 5.8.4.21112, Zoom Meeting SDK para Android antes de la versión 5.7.6. 1922, Zoom Meeting SDK para iOS antes de la versión 5.7.6.1082, Zoom Meeting SDK para macOS antes de la versión 5.7.6.1340, Zoom Meeting SDK para Windows antes de la versión 5.7.6.1081, Zoom Video SDK (para Android, iOS, macOS y Windows) antes de la versión 1.1.2, Zoom on-premise Meeting Connector antes de la versión 4. 8.12.20211115, Zoom on-premise Meeting Connector MMR antes de la versión 4.8.12.20211115, Zoom on-premise Recording Connector antes de la versión 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector antes de la versión 4.4.7266. 20211117, Zoom on-premise Virtual Room Connector Load Balancer antes de la versión 2.5.5692.20211117, Zoom Hybrid Zproxy antes de la versión 1.0.1058.20211116, y Zoom Hybrid MMR antes de la versión 4.6.20211116.131_x86-64 que potencialmente permitía la exposición del estado de la memoria del proceso. Este problema podría ser utilizado para potencialmente obtener información sobre áreas arbitrarias de la memoria del producto
Zoom suffers from an information leak vulnerability in the MMR server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-09 CVE Reserved
- 2021-11-24 CVE Published
- 2024-08-09 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/165419/Zoom-MMR-Server-Information-Leak.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://explore.zoom.us/en/trust/security/security-bulletin | 2022-07-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zoom Search vendor "Zoom" | Meetings Search vendor "Zoom" for product "Meetings" | < 5.8.3 Search vendor "Zoom" for product "Meetings" and version " < 5.8.3" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings Search vendor "Zoom" for product "Meetings" | < 5.8.4 Search vendor "Zoom" for product "Meetings" and version " < 5.8.4" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings Search vendor "Zoom" for product "Meetings" | < 5.8.4 Search vendor "Zoom" for product "Meetings" and version " < 5.8.4" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings Search vendor "Zoom" for product "Meetings" | < 5.8.4 Search vendor "Zoom" for product "Meetings" and version " < 5.8.4" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings Search vendor "Zoom" for product "Meetings" | < 5.8.4 Search vendor "Zoom" for product "Meetings" and version " < 5.8.4" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings For Blackberry Search vendor "Zoom" for product "Meetings For Blackberry" | < 5.8.1 Search vendor "Zoom" for product "Meetings For Blackberry" and version " < 5.8.1" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings For Blackberry Search vendor "Zoom" for product "Meetings For Blackberry" | < 5.8.1 Search vendor "Zoom" for product "Meetings For Blackberry" and version " < 5.8.1" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings For Intune Search vendor "Zoom" for product "Meetings For Intune" | < 5.8.4 Search vendor "Zoom" for product "Meetings For Intune" and version " < 5.8.4" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings For Intune Search vendor "Zoom" for product "Meetings For Intune" | < 5.8.4 Search vendor "Zoom" for product "Meetings For Intune" and version " < 5.8.4" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Rooms For Conference Rooms Search vendor "Zoom" for product "Rooms For Conference Rooms" | < 5.8.3 Search vendor "Zoom" for product "Rooms For Conference Rooms" and version " < 5.8.3" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Rooms For Conference Rooms Search vendor "Zoom" for product "Rooms For Conference Rooms" | < 5.8.3 Search vendor "Zoom" for product "Rooms For Conference Rooms" and version " < 5.8.3" | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Rooms For Conference Rooms Search vendor "Zoom" for product "Rooms For Conference Rooms" | < 5.8.3 Search vendor "Zoom" for product "Rooms For Conference Rooms" and version " < 5.8.3" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Controllers For Zoom Rooms Search vendor "Zoom" for product "Controllers For Zoom Rooms" | < 5.8.3 Search vendor "Zoom" for product "Controllers For Zoom Rooms" and version " < 5.8.3" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Controllers For Zoom Rooms Search vendor "Zoom" for product "Controllers For Zoom Rooms" | < 5.8.3 Search vendor "Zoom" for product "Controllers For Zoom Rooms" and version " < 5.8.3" | - |
Affected
| in | Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Controllers For Zoom Rooms Search vendor "Zoom" for product "Controllers For Zoom Rooms" | < 5.8.3 Search vendor "Zoom" for product "Controllers For Zoom Rooms" and version " < 5.8.3" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|
Zoom Search vendor "Zoom" | Meetings For Chrome Os Search vendor "Zoom" for product "Meetings For Chrome Os" | < 5.0.1 Search vendor "Zoom" for product "Meetings For Chrome Os" and version " < 5.0.1" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Virtual Desktop Infrastructure Search vendor "Zoom" for product "Virtual Desktop Infrastructure" | < 5.8.4 Search vendor "Zoom" for product "Virtual Desktop Infrastructure" and version " < 5.8.4" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Android Meeting Sdk Search vendor "Zoom" for product "Android Meeting Sdk" | < 5.7.6.1922 Search vendor "Zoom" for product "Android Meeting Sdk" and version " < 5.7.6.1922" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Iphone Os Meeting Sdk Search vendor "Zoom" for product "Iphone Os Meeting Sdk" | < 5.7.6.1082 Search vendor "Zoom" for product "Iphone Os Meeting Sdk" and version " < 5.7.6.1082" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Macos Meeting Sdk Search vendor "Zoom" for product "Macos Meeting Sdk" | < 5.7.6.1340 Search vendor "Zoom" for product "Macos Meeting Sdk" and version " < 5.7.6.1340" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Windows Meeting Sdk Search vendor "Zoom" for product "Windows Meeting Sdk" | < 5.7.6.1081 Search vendor "Zoom" for product "Windows Meeting Sdk" and version " < 5.7.6.1081" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Android Video Sdk Search vendor "Zoom" for product "Android Video Sdk" | < 1.1.2 Search vendor "Zoom" for product "Android Video Sdk" and version " < 1.1.2" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Iphone Os Video Sdk Search vendor "Zoom" for product "Iphone Os Video Sdk" | < 1.1.2 Search vendor "Zoom" for product "Iphone Os Video Sdk" and version " < 1.1.2" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Macos Video Sdk Search vendor "Zoom" for product "Macos Video Sdk" | < 1.1.2 Search vendor "Zoom" for product "Macos Video Sdk" and version " < 1.1.2" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Windows Video Sdk Search vendor "Zoom" for product "Windows Video Sdk" | < 1.1.2 Search vendor "Zoom" for product "Windows Video Sdk" and version " < 1.1.2" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Hybrid Mmr Search vendor "Zoom" for product "Hybrid Mmr" | < 4.6.20211116.131 Search vendor "Zoom" for product "Hybrid Mmr" and version " < 4.6.20211116.131" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Hybrid Zproxy Search vendor "Zoom" for product "Hybrid Zproxy" | < 1.0.1058.20211116 Search vendor "Zoom" for product "Hybrid Zproxy" and version " < 1.0.1058.20211116" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom On-premise Meeting Connector Controller Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Controller" | < 4.8.12.20211115 Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Controller" and version " < 4.8.12.20211115" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom On-premise Meeting Connector Mmr Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Mmr" | < 4.8.12.20211115 Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Mmr" and version " < 4.8.12.20211115" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom On-premise Recording Connector Search vendor "Zoom" for product "Zoom On-premise Recording Connector" | < 5.1.0.65.20211116 Search vendor "Zoom" for product "Zoom On-premise Recording Connector" and version " < 5.1.0.65.20211116" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom On-premise Virtual Room Connector Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector" | < 4.4.7266.20211117 Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector" and version " < 4.4.7266.20211117" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Zoom On-premise Virtual Room Connector Load Balancer Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector Load Balancer" | < 2.5.5692.20211117 Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector Load Balancer" and version " < 2.5.5692.20211117" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Vdi Azure Virtual Desktop Search vendor "Zoom" for product "Vdi Azure Virtual Desktop" | < 5.8.4.21112 Search vendor "Zoom" for product "Vdi Azure Virtual Desktop" and version " < 5.8.4.21112" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Vdi Citrix Search vendor "Zoom" for product "Vdi Citrix" | < 5.8.4.21112 Search vendor "Zoom" for product "Vdi Citrix" and version " < 5.8.4.21112" | - |
Affected
| ||||||
Zoom Search vendor "Zoom" | Vdi Vmware Search vendor "Zoom" for product "Vdi Vmware" | < 5.8.4.21112 Search vendor "Zoom" for product "Vdi Vmware" and version " < 5.8.4.21112" | - |
Affected
|