Resource Exhaustion Vulnerability in Zoom On-Premise Meeting Connector
CVE-2021-34415
7.5HIGH
Key Information:
- Vendor
Zoom
- Vendor
- CVE Published:
- 27 September 2021
What is CVE-2021-34415?
The On-Premise Meeting Connector for Zoom has a vulnerability in its Zone Controller service that fails to properly verify the 'cnt' field in incoming network packets. This oversight can allow an attacker to exploit the system, leading to resource exhaustion and potential system crashes. Users are urged to update to the latest version to ensure their systems are secure.
Affected Version(s)
Zoom On-Premise Meeting Connector Controller The Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205