PT-2022-3248 · Zoom · Zoom Client For Meetings+1

Ivan Fratric

·

Published

2022-01-07

·

Updated

2022-07-07

·

CVE-2022-22787

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoom Client for Meetings versions prior to 5.10.0
Description The issue is related to the improper validation of the hostname during a server switch request. This could be used in a sophisticated attack to trick an unsuspecting user's client into connecting to a malicious server when attempting to use Zoom services. The vulnerability may allow a remote attacker to perform a man-in-the-middle attack.
Recommendations For versions prior to 5.10.0, update to version 5.10.0 or later to resolve the issue. As a temporary workaround, consider restricting server switch requests to trusted hosts until a patch is applied. Avoid using the Zoom Client for Meetings until the issue is resolved.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03955
CVE-2022-22787

Affected Products

Zoom Client For Meetings
Zoom