VYPR
Unrated severityNVD Advisory· Published Sep 27, 2021· Updated Aug 4, 2024

CVE-2021-34416

CVE-2021-34416

Description

The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal administrators.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The network address settings portal in multiple Zoom on-premise products lacks input validation, allowing authenticated administrators to inject commands remotely.

Vulnerability

The network address administrative settings web portal in multiple Zoom on-premise products fails to validate user-supplied input when updating network configuration. This input validation flaw allows remote command injection on the affected on-premise image. The vulnerability impacts Zoom on-premise Meeting Connector versions before 4.6.360.20210325, Zoom on-premise Meeting Connector MMR versions before 4.6.360.20210325, Zoom on-premise Recording Connector versions before 3.8.44.20210326, Zoom on-premise Virtual Room Connector versions before 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer versions before 2.5.5495.20210326 [1].

Exploitation

An attacker must be authenticated as a web portal administrator to exploit this vulnerability. By sending crafted requests to the network configuration update endpoint, the attacker can inject arbitrary commands. No user interaction beyond the administrator's own actions is required. The injection occurs because the input is not properly sanitized before being processed [1].

Impact

Successful exploitation allows a remote, authenticated administrator to execute arbitrary commands on the underlying on-premise image. This can lead to full system compromise, including data exfiltration, modification of system configuration, and potential lateral movement within the network. The attacker gains command injection at the level of the web application, but the commands run with the privileges of the affected process, which may be elevated [1].

Mitigation

Zoom has released fixed versions for all affected products: Meeting Connector version 4.6.360.20210325, Meeting Connector MMR version 4.6.360.20210325, Recording Connector version 3.8.44.20210326, Virtual Room Connector version 4.4.6752.20210326, and Virtual Room Connector Load Balancer version 2.5.5495.20210326. Users should update to these versions or later to remediate the vulnerability. No workarounds are mentioned in the available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.