// For flags

CVE-2021-34424

Process memory exposure in Zoom Client and other products

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112, Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112, Zoom Meeting SDK for Android before version 5.7.6.1922, Zoom Meeting SDK for iOS before version 5.7.6.1082, Zoom Meeting SDK for macOS before version 5.7.6.1340, Zoom Meeting SDK for Windows before version 5.7.6.1081, Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2, Zoom on-premise Meeting Connector before version 4.8.12.20211115, Zoom on-premise Meeting Connector MMR before version 4.8.12.20211115, Zoom on-premise Recording Connector before version 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector before version 4.4.7266.20211117, Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117, Zoom Hybrid Zproxy before version 1.0.1058.20211116, and Zoom Hybrid MMR before version 4.6.20211116.131_x86-64 which potentially allowed for the exposure of the state of process memory. This issue could be used to potentially gain insight into arbitrary areas of the product's memory.

Se ha detectado una vulnerabilidad en Zoom Client for Meetings (para Android, iOS, Linux, macOS y Windows) antes de la versión 5.8.4, Zoom Client for Meetings for Blackberry (para Android e iOS) antes de la versión 5.8.1, Zoom Client for Meetings for intune (para Android e iOS) antes de la versión 5.8.4, Zoom Client for Meetings for Chrome OS antes de la versión 5.0.1, Zoom Rooms for Conference Room (para Android, AndroidBali, macOS y Windows) antes de la versión 5.8. 3, Controllers for Zoom Rooms (para Android, iOS y Windows) antes de la versión 5.8.3, Zoom VDI Windows Meeting Client antes de la versión 5.8.4, Zoom VDI Azure Virtual Desktop Plugins (para Windows x86 o x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) antes de la versión 5. 8.4.21112, Zoom VDI Citrix Plugins (para Windows x86 o x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) antes de la versión 5.8.4. 21112, Zoom VDI VMware Plugins (para Windows x86 o x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) antes de la versión 5.8.4.21112, Zoom Meeting SDK para Android antes de la versión 5.7.6. 1922, Zoom Meeting SDK para iOS antes de la versión 5.7.6.1082, Zoom Meeting SDK para macOS antes de la versión 5.7.6.1340, Zoom Meeting SDK para Windows antes de la versión 5.7.6.1081, Zoom Video SDK (para Android, iOS, macOS y Windows) antes de la versión 1.1.2, Zoom on-premise Meeting Connector antes de la versión 4. 8.12.20211115, Zoom on-premise Meeting Connector MMR antes de la versión 4.8.12.20211115, Zoom on-premise Recording Connector antes de la versión 5.1.0.65.20211116, Zoom on-premise Virtual Room Connector antes de la versión 4.4.7266. 20211117, Zoom on-premise Virtual Room Connector Load Balancer antes de la versión 2.5.5692.20211117, Zoom Hybrid Zproxy antes de la versión 1.0.1058.20211116, y Zoom Hybrid MMR antes de la versión 4.6.20211116.131_x86-64 que potencialmente permitía la exposición del estado de la memoria del proceso. Este problema podría ser utilizado para potencialmente obtener información sobre áreas arbitrarias de la memoria del producto

Zoom suffers from an information leak vulnerability in the MMR server.

*Credits: Natalie Silvanovich of Google Project Zero
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-09 CVE Reserved
  • 2021-11-24 CVE Published
  • 2024-08-09 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-125: Out-of-bounds Read
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.8.3
Search vendor "Zoom" for product "Meetings" and version " < 5.8.3"
-
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
--
Safe
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.8.4
Search vendor "Zoom" for product "Meetings" and version " < 5.8.4"
-
Affected
in Apple
Search vendor "Apple"
Macos
Search vendor "Apple" for product "Macos"
--
Safe
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.8.4
Search vendor "Zoom" for product "Meetings" and version " < 5.8.4"
-
Affected
in Apple
Search vendor "Apple"
Iphone Os
Search vendor "Apple" for product "Iphone Os"
--
Safe
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.8.4
Search vendor "Zoom" for product "Meetings" and version " < 5.8.4"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.8.4
Search vendor "Zoom" for product "Meetings" and version " < 5.8.4"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Zoom
Search vendor "Zoom"
Meetings For Blackberry
Search vendor "Zoom" for product "Meetings For Blackberry"
< 5.8.1
Search vendor "Zoom" for product "Meetings For Blackberry" and version " < 5.8.1"
-
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
--
Safe
Zoom
Search vendor "Zoom"
Meetings For Blackberry
Search vendor "Zoom" for product "Meetings For Blackberry"
< 5.8.1
Search vendor "Zoom" for product "Meetings For Blackberry" and version " < 5.8.1"
-
Affected
in Apple
Search vendor "Apple"
Iphone Os
Search vendor "Apple" for product "Iphone Os"
--
Safe
Zoom
Search vendor "Zoom"
Meetings For Intune
Search vendor "Zoom" for product "Meetings For Intune"
< 5.8.4
Search vendor "Zoom" for product "Meetings For Intune" and version " < 5.8.4"
-
Affected
in Apple
Search vendor "Apple"
Iphone Os
Search vendor "Apple" for product "Iphone Os"
--
Safe
Zoom
Search vendor "Zoom"
Meetings For Intune
Search vendor "Zoom" for product "Meetings For Intune"
< 5.8.4
Search vendor "Zoom" for product "Meetings For Intune" and version " < 5.8.4"
-
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
--
Safe
Zoom
Search vendor "Zoom"
Rooms For Conference Rooms
Search vendor "Zoom" for product "Rooms For Conference Rooms"
< 5.8.3
Search vendor "Zoom" for product "Rooms For Conference Rooms" and version " < 5.8.3"
-
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
--
Safe
Zoom
Search vendor "Zoom"
Rooms For Conference Rooms
Search vendor "Zoom" for product "Rooms For Conference Rooms"
< 5.8.3
Search vendor "Zoom" for product "Rooms For Conference Rooms" and version " < 5.8.3"
-
Affected
in Apple
Search vendor "Apple"
Macos
Search vendor "Apple" for product "Macos"
--
Safe
Zoom
Search vendor "Zoom"
Rooms For Conference Rooms
Search vendor "Zoom" for product "Rooms For Conference Rooms"
< 5.8.3
Search vendor "Zoom" for product "Rooms For Conference Rooms" and version " < 5.8.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Zoom
Search vendor "Zoom"
Controllers For Zoom Rooms
Search vendor "Zoom" for product "Controllers For Zoom Rooms"
< 5.8.3
Search vendor "Zoom" for product "Controllers For Zoom Rooms" and version " < 5.8.3"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Zoom
Search vendor "Zoom"
Controllers For Zoom Rooms
Search vendor "Zoom" for product "Controllers For Zoom Rooms"
< 5.8.3
Search vendor "Zoom" for product "Controllers For Zoom Rooms" and version " < 5.8.3"
-
Affected
in Apple
Search vendor "Apple"
Iphone Os
Search vendor "Apple" for product "Iphone Os"
--
Safe
Zoom
Search vendor "Zoom"
Controllers For Zoom Rooms
Search vendor "Zoom" for product "Controllers For Zoom Rooms"
< 5.8.3
Search vendor "Zoom" for product "Controllers For Zoom Rooms" and version " < 5.8.3"
-
Affected
in Google
Search vendor "Google"
Android
Search vendor "Google" for product "Android"
--
Safe
Zoom
Search vendor "Zoom"
Meetings For Chrome Os
Search vendor "Zoom" for product "Meetings For Chrome Os"
< 5.0.1
Search vendor "Zoom" for product "Meetings For Chrome Os" and version " < 5.0.1"
-
Affected
Zoom
Search vendor "Zoom"
Virtual Desktop Infrastructure
Search vendor "Zoom" for product "Virtual Desktop Infrastructure"
< 5.8.4
Search vendor "Zoom" for product "Virtual Desktop Infrastructure" and version " < 5.8.4"
-
Affected
Zoom
Search vendor "Zoom"
Android Meeting Sdk
Search vendor "Zoom" for product "Android Meeting Sdk"
< 5.7.6.1922
Search vendor "Zoom" for product "Android Meeting Sdk" and version " < 5.7.6.1922"
-
Affected
Zoom
Search vendor "Zoom"
Iphone Os Meeting Sdk
Search vendor "Zoom" for product "Iphone Os Meeting Sdk"
< 5.7.6.1082
Search vendor "Zoom" for product "Iphone Os Meeting Sdk" and version " < 5.7.6.1082"
-
Affected
Zoom
Search vendor "Zoom"
Macos Meeting Sdk
Search vendor "Zoom" for product "Macos Meeting Sdk"
< 5.7.6.1340
Search vendor "Zoom" for product "Macos Meeting Sdk" and version " < 5.7.6.1340"
-
Affected
Zoom
Search vendor "Zoom"
Windows Meeting Sdk
Search vendor "Zoom" for product "Windows Meeting Sdk"
< 5.7.6.1081
Search vendor "Zoom" for product "Windows Meeting Sdk" and version " < 5.7.6.1081"
-
Affected
Zoom
Search vendor "Zoom"
Android Video Sdk
Search vendor "Zoom" for product "Android Video Sdk"
< 1.1.2
Search vendor "Zoom" for product "Android Video Sdk" and version " < 1.1.2"
-
Affected
Zoom
Search vendor "Zoom"
Iphone Os Video Sdk
Search vendor "Zoom" for product "Iphone Os Video Sdk"
< 1.1.2
Search vendor "Zoom" for product "Iphone Os Video Sdk" and version " < 1.1.2"
-
Affected
Zoom
Search vendor "Zoom"
Macos Video Sdk
Search vendor "Zoom" for product "Macos Video Sdk"
< 1.1.2
Search vendor "Zoom" for product "Macos Video Sdk" and version " < 1.1.2"
-
Affected
Zoom
Search vendor "Zoom"
Windows Video Sdk
Search vendor "Zoom" for product "Windows Video Sdk"
< 1.1.2
Search vendor "Zoom" for product "Windows Video Sdk" and version " < 1.1.2"
-
Affected
Zoom
Search vendor "Zoom"
Hybrid Mmr
Search vendor "Zoom" for product "Hybrid Mmr"
< 4.6.20211116.131
Search vendor "Zoom" for product "Hybrid Mmr" and version " < 4.6.20211116.131"
-
Affected
Zoom
Search vendor "Zoom"
Hybrid Zproxy
Search vendor "Zoom" for product "Hybrid Zproxy"
< 1.0.1058.20211116
Search vendor "Zoom" for product "Hybrid Zproxy" and version " < 1.0.1058.20211116"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Meeting Connector Controller
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Controller"
< 4.8.12.20211115
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Controller" and version " < 4.8.12.20211115"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Meeting Connector Mmr
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Mmr"
< 4.8.12.20211115
Search vendor "Zoom" for product "Zoom On-premise Meeting Connector Mmr" and version " < 4.8.12.20211115"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Recording Connector
Search vendor "Zoom" for product "Zoom On-premise Recording Connector"
< 5.1.0.65.20211116
Search vendor "Zoom" for product "Zoom On-premise Recording Connector" and version " < 5.1.0.65.20211116"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Virtual Room Connector
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector"
< 4.4.7266.20211117
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector" and version " < 4.4.7266.20211117"
-
Affected
Zoom
Search vendor "Zoom"
Zoom On-premise Virtual Room Connector Load Balancer
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector Load Balancer"
< 2.5.5692.20211117
Search vendor "Zoom" for product "Zoom On-premise Virtual Room Connector Load Balancer" and version " < 2.5.5692.20211117"
-
Affected
Zoom
Search vendor "Zoom"
Vdi Azure Virtual Desktop
Search vendor "Zoom" for product "Vdi Azure Virtual Desktop"
< 5.8.4.21112
Search vendor "Zoom" for product "Vdi Azure Virtual Desktop" and version " < 5.8.4.21112"
-
Affected
Zoom
Search vendor "Zoom"
Vdi Citrix
Search vendor "Zoom" for product "Vdi Citrix"
< 5.8.4.21112
Search vendor "Zoom" for product "Vdi Citrix" and version " < 5.8.4.21112"
-
Affected
Zoom
Search vendor "Zoom"
Vdi Vmware
Search vendor "Zoom" for product "Vdi Vmware"
< 5.8.4.21112
Search vendor "Zoom" for product "Vdi Vmware" and version " < 5.8.4.21112"
-
Affected