Resource exhaustion in Zoom Video Communications, Inc. products - CVE-2022-22780
Published: May 24, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing .zip archives. A remote attacker can pass a specially crafted ZIP archive, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
How to mitigate CVE-2022-22780
Zoom Workplace Desktop App for Windows - update to 5.6.3 751
Zoom Workplace Desktop App for macOS - update to 5.7.3 809
Zoom Workplace App for Android - update to 5.8.6 3139
Zoom Workplace Desktop App for Linux - update to 5.8.6 739