CVE-2022-22786
Summary
| CVE | CVE-2022-22786 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-18 16:15:00 UTC |
| Updated | 2022-05-27 15:29:00 UTC |
| Description | The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version. |
Risk And Classification
Problem Types: CWE-494
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin | Zoom | MISC | explore.zoom.us | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ivan Fratric of Google Project Zero
Legacy QID Mappings
- 376640 Zoom Package Downgrade Vulnerability (ZSB-22008)