CVE-2022-28763
Summary
| CVE | CVE-2022-28763 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-31 20:15:00 UTC |
| Updated | 2022-11-01 19:43:00 UTC |
| Description | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377694 Zoom Client for Meetings Multiple Security Vulnerabilities (ZSB-22024)
- 377707 Zoom VDI Uniform Resource Locator (URL) Parsing Vulnerability (ZSB-22024)