CVE-2021-34823 describes a critical vulnerability in the ON24 ScreenShare plugin for macOS (versions prior to 2.0) that allows unauthenticated remote file access. Attackers can exploit an XML External Entity (XXE) flaw within a built-in HTTP server to read local files from the macOS system and exfiltrate them to remote machines. With a CVSS score of 9.1 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to high confidentiality and integrity impacts. Despite its severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0CPE matchmatch criteria | cpe:2.3:a:on24:screenshare:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.