#VU69355 Insecure DLL loading in Zoom Video Communications, Inc. products - CVE-2022-28766
Published: November 16, 2022
Vulnerability identifier: #VU69355
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-28766
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Zoom Workplace Desktop App for Windows
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
Zoom Workplace Desktop App for Windows
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
Software vendor:
Zoom Video Communications, Inc.
Zoom Video Communications, Inc.
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner. A local user can force the application to load a malicious .dll file and execute arbitrary code on the system in the context of the Zoom client.
Note, the vulnerability affects only Windows 32-bit clients.
Remediation
Install updates from vendor's website.