Reliance on Untrusted Inputs in a Security Decision in Zoom Rooms Client for Windows and Zoom Workplace Desktop App for Windows - CVE-2022-22786
Published: May 24, 2022
Vulnerability identifier: #VU63590
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22786
CWE-ID: CWE-807
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to improper checking of the currently installed software version when performing software update. A remote attacker can trick the victim into installing an older software version.
Affected software
Zoom Rooms Client for Windows
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for Windows
How to mitigate CVE-2022-22786
Install updates from vendor's website.
Zoom Rooms Client for Windows - update to 5.10.0 1251
Zoom Workplace Desktop App for Windows - update to 5.10.0 4306
Zoom Workplace Desktop App for Windows - update to 5.10.0 4306