CVE-2021-34424 is a memory exposure vulnerability affecting numerous Zoom products across various platforms, including Zoom Client for Meetings, Zoom Rooms, Zoom VDI clients, and several Zoom SDKs and on-premise connectors. This flaw could allow an attacker to gain insight into arbitrary areas of the product's memory. With a CVSS score of 7.5 (High), it is a network-exploitable vulnerability requiring no user interaction, potentially leading to high confidentiality impact. While the vulnerability has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.8.3CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:*:*:* | ||
< 5.8.4CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:*:*:* | ||
< 5.8.1CPE matchmatch criteria | cpe:2.3:a:zoom:meetings_for_blackberry:*:*:*:*:*:*:*:* | ||
< 5.8.4CPE matchmatch criteria | cpe:2.3:a:zoom:meetings_for_intune:*:*:*:*:*:*:*:* | ||
< 5.0.1CPE matchmatch criteria | cpe:2.3:a:zoom:meetings_for_chrome_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.