XML injection in Zoom Video Communications, Inc. products - CVE-2022-22784
Published: May 24, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to improper input validation when processing XML data inside XMPP messages. A remote attacker can send a specially crafted chat message to break out of the current XMPP message context and spoof messages from other application users or from server.
Affected software
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Workplace App for iOS
Zoom Workplace App for Android
How to mitigate CVE-2022-22784
Zoom Workplace Desktop App for macOS - update to 5.10.0 5714
Zoom Workplace App for iOS - update to 5.10.0 2988
Zoom Workplace App for Android - update to 5.10.0 5129
Zoom Workplace Desktop App for Linux - update to 5.10.0 2450