VYPR
Unrated severityNVD Advisory· Published Sep 27, 2021· Updated Aug 4, 2024

CVE-2021-34414

CVE-2021-34414

Description

The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal administrator.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Input validation failure in Zoom on-premise Meeting Connector network proxy page allows remote command injection by a web portal administrator.

Vulnerability

The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller, Meeting Connector MMR, Recording Connector, Virtual Room Connector, and Virtual Room Connector Load Balancer fails to validate input sent in requests to update the network proxy configuration. This vulnerability affects the following products before the specified versions: Meeting Connector Controller before version 4.6.348.20201217, Meeting Connector MMR before version 4.6.348.20201217, Recording Connector before version 3.8.42.20200905, Virtual Room Connector before version 4.4.6620.20201110, and Virtual Room Connector Load Balancer before version 2.5.5495.20210326 [1].

Exploitation

A web portal administrator can send a crafted request to the network proxy configuration update endpoint. The lack of input validation in the affected component allows the attacker to inject arbitrary commands. No additional authentication beyond administrator privileges is required, and the attack does not involve user interaction. The attacker must have network access to the on-premise deployment's web portal [1].

Impact

Successful exploitation results in remote command injection on the underlying on-premise image. The attacker gains the ability to execute arbitrary commands with the privileges of the web portal service, potentially leading to full compromise of the Zoom on-premise component. The scope of impact includes confidentiality, integrity, and availability of the affected system [1].

Mitigation

Zoom recommends users update to the latest version of the affected products to obtain security fixes. The fixes are available in the following versions and release dates: Meeting Connector Controller and MMR version 4.6.348.20201217, Recording Connector version 3.8.42.20200905, Virtual Room Connector version 4.4.6620.20201110, and Virtual Room Connector Load Balancer version 2.5.5495.20210326 [1]. No workarounds are described in the available references.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.