PT-2022-15673 · Zoom · Zoom Client For Meetings

Patrick Wardle

·

Published

2022-04-28

·

Updated

2022-05-09

·

CVE-2022-22781

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zoom Client for Meetings for MacOS versions prior to 5.9.6
Description The issue arises from the failure to properly check the package version during the update process. This could allow a malicious actor to update a user's currently installed version to a less secure version.
Recommendations For versions prior to 5.9.6, update to version 5.9.6 or later to resolve the issue. As a temporary workaround, consider disabling automatic updates until a patch is applied. Restrict access to the update mechanism to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22781

Affected Products

Zoom Client For Meetings