Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-22785

 

Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-22785

Published: May 24, 2022


Vulnerability identifier: #VU63588
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22785
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to Zoom client fails to properly constrain client session cookies to Zoom domains. A remote attacker can force unsuspecting users send Zoom-scoped session cookies to a non-Zoom domain and perform spoofing of a Zoom user.


Affected software

Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Workplace App for iOS
Zoom Workplace App for Android

How to mitigate CVE-2022-22785

Install updates from vendor's website.

Zoom Workplace Desktop App for Windows - update to 5.10.0 4306
Zoom Workplace Desktop App for macOS - update to 5.10.0 5714
Zoom Workplace App for iOS - update to 5.10.0 2988
Zoom Workplace App for Android - update to 5.10.0 5129
Zoom Workplace Desktop App for Linux - update to 5.10.0 2450

External References

Related Security Bulletins