CVE-2022-22788
Published: Jun 15, 2022
Modified: Sep 16, 2024
CVSS v3.1
7.1
Description
The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.
| Vendor | Product | Versions |
|---|---|---|
Zoom Video Communications Inc | Zoom Client for Meetings | affected unspecified - < 5.10.3 |
Zoom Video Communications Inc | All Zoom Rooms for Conference Room for Windows | affected unspecified - < 5.10.3 |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now