PT-2022-19217 · Zoom · Zoom Client For Meetings+1

Published

2022-10-26

·

Updated

2022-11-01

·

CVE-2022-28763

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Client for Meetings versions prior to 5.12.2
Description The issue allows a malicious Zoom meeting URL to direct the user to connect to an arbitrary network address, potentially leading to additional attacks, including session takeovers, when the URL is opened.
Recommendations For versions prior to 5.12.2, update to version 5.12.2 or later to resolve the issue. As a temporary workaround, consider avoiding the use of potentially malicious Zoom meeting URLs until the update is applied. Restrict access to untrusted URLs to minimize the risk of exploitation.

Fix

Open Redirect

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-28763

Affected Products

Zoom Client For Meetings
Zoom