Resource exhaustion in Zoom Video Communications, Inc. products - CVE-2022-22780

 

Resource exhaustion in Zoom Video Communications, Inc. products - CVE-2022-22780

Published: May 24, 2022


Vulnerability identifier: #VU63593
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22780
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing .zip archives. A remote attacker can pass a specially crafted ZIP archive, trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux

How to mitigate CVE-2022-22780

Install updates from vendor's website.

Zoom Workplace App for iOS - update to 5.9.0 2086
Zoom Workplace Desktop App for Windows - update to 5.6.3 751
Zoom Workplace Desktop App for macOS - update to 5.7.3 809
Zoom Workplace App for Android - update to 5.8.6 3139
Zoom Workplace Desktop App for Linux - update to 5.8.6 739

External References

Related Security Bulletins