{"api_version":"1","generated_at":"2026-07-24T23:42:51+00:00","cve":"CVE-2022-22781","urls":{"html":"https://cve.report/CVE-2022-22781","api":"https://cve.report/api/cve/CVE-2022-22781.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-22781","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-22781"},"summary":{"title":"CVE-2022-22781","description":"The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.","state":"PUBLIC","assigner":"security@zoom.us","published_at":"2022-04-28 15:15:00","updated_at":"2022-05-09 18:21:00"},"problem_types":["CWE-354"],"metrics":[],"references":[{"url":"https://explore.zoom.us/en/trust/security/security-bulletin/","name":"https://explore.zoom.us/en/trust/security/security-bulletin/","refsource":"MISC","tags":[],"title":"Security Bulletins | Zoom","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-22781","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22781","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Patrick Wardle of Objective-See","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"22781","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"meetings","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"macos","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-22781","qid":"376591","title":"Zoom Client Update package downgrade for MAC"}]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"Zoom Video Communications Inc","ASSIGNER":"security@zoom.us","DATE_PUBLIC":"2022-04-27T12:00:00.000Z","ID":"CVE-2022-22781","STATE":"PUBLIC","TITLE":"Update package downgrade in Zoom Client for Meetings for MacOS"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Zoom Client for Meetings for MacOS (Standard and for IT Admin)","version":{"version_data":[{"version_affected":"<","version_value":"5.9.6"}]}}]},"vendor_name":"Zoom Video Communications Inc"}]}},"credit":[{"lang":"eng","value":"Patrick Wardle of Objective-See"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Use of Less Trusted Source"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://explore.zoom.us/en/trust/security/security-bulletin/","name":"https://explore.zoom.us/en/trust/security/security-bulletin/"}]},"source":{"discovery":"USER"}},"nvd":{"publishedDate":"2022-04-28 15:15:00","lastModifiedDate":"2022-05-09 18:21:00","problem_types":["CWE-354"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:*","versionEndExcluding":"5.9.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"22781","Ordinal":"225235","Title":"CVE-2022-22781","CVE":"CVE-2022-22781","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"22781","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}