Input validation error in Zoom Video Communications, Inc. products - CVE-2022-28755

 

Input validation error in Zoom Video Communications, Inc. products - CVE-2022-28755

Published: August 10, 2022 / Updated: August 27, 2022


Vulnerability identifier: #VU66376
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28755
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when parsing meeting URL. A remote attacker can trick the victim to follow a specially crafted URL, which can direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.


Affected software

Zoom Workplace App for iOS
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Virtual Desktop Infrastructure (VDI)

How to mitigate CVE-2022-28755

Install updates from vendor's website.

Zoom Workplace App for iOS - update to 5.11.1 3887
Zoom Workplace Desktop App for Windows - update to 5.11.0 6569
Zoom Workplace Desktop App for macOS - update to 5.11.3 9065
Virtual Desktop Infrastructure (VDI) - update to 5.10.7.21358
Zoom Workplace App for Android - update to 5.11.1 6880
Zoom Workplace Desktop App for Linux - update to 5.11.1 3595

External References

Related Security Bulletins