Zoom 用戶端和其他產品發生處理記憶體暴露
- ZSB-21020
- CVE-2021-34424
- 高
- 5.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
本佈告欄中「受影響的產品」區段所列出的產品中發現漏洞,此漏洞可能會暴露處理記憶體的狀態。此問題可用來獲取任意區域的產品記憶體狀態。Zoom 在下面區段列出的最新版本產品中已解決該問題。使用者可套用目前的更新或下載最新的 Zoom 軟體 (含目前所有安全更新),以保護自己的安全。
- Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4
- Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1
- Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4
- Zoom Client for Meetings for Chrome OS before version 5.0.1
- Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3
- Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3
- Zoom VDI Windows Meeting Client before version 5.8.4
- Zoom VDI Azure Virtual Desktop Plugins (for Windows x86 or x64, IGEL x64, Ubuntu x64, HP ThinPro OS x64) before version 5.8.4.21112
- Zoom VDI Citrix Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112
- Zoom VDI VMware Plugins (for Windows x86 or x64, Mac Universal Installer & Uninstaller, IGEL x64, eLux RP6 x64, HP ThinPro OS x64, Ubuntu x64, CentOS x 64, Dell ThinOS) before version 5.8.4.21112
- Zoom Meeting SDK for Android before version 5.7.6.1922
- Zoom Meeting SDK for iOS before version 5.7.6.1082
- Zoom Meeting SDK for Windows before version 5.7.6.1081
- Zoom Meeting SDK for Mac before version 5.7.6.1340
- Zoom Video SDK (for Android, iOS, macOS, and Windows) before version 1.1.2
- Zoom On-Premise Meeting Connector before version 4.8.12.20211115
- Zoom On-Premise Meeting Connector MMR before version 4.8.12.20211115
- Zoom On-Premise Recording Connector before version 5.1.0.65.20211116
- Zoom On-Premise Virtual Room Connector before version 4.4.7266.20211117
- Zoom On-Premise Virtual Room Connector Load Balancer before version 2.5.5692.20211117
- Zoom Hybrid Zproxy before version 1.0.1058.20211116
- Zoom Hybrid MMR before version 4.6.20211116.131_x86-64
由 Google Project Zero 的 Natalie Silvanovich 舉報
| Revision | 日期 | 說明 |
|---|---|---|
| 1.0 | 11/24/2021 | 首次出版 |