CVE-2022-28764
Summary
| CVE | CVE-2022-28764 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-14 21:15:00 UTC |
| Updated | 2022-11-17 22:03:00 UTC |
| Description | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377756 Zoom Client for Meetings Multiple Security Vulnerabilities (ZSB-22025)
- 377758 Zoom VDI Local Information Exposure Vulnerability (ZSB-22025)