Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22786


The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.


Published

2022-05-18T16:15:08.750

Last Modified

2024-11-21T06:47:26.893

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-494

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zoom meetings < 5.10.0 Yes
Application zoom rooms < 5.10.0 Yes

References