{"api_version":"1","generated_at":"2026-07-23T19:45:51+00:00","cve":"CVE-2022-22788","urls":{"html":"https://cve.report/CVE-2022-22788","api":"https://cve.report/api/cve/CVE-2022-22788.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-22788","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-22788"},"summary":{"title":"CVE-2022-22788","description":"The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.","state":"PUBLIC","assigner":"security@zoom.us","published_at":"2022-06-15 21:15:00","updated_at":"2022-06-27 17:54:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://explore.zoom.us/en/trust/security/security-bulletin/","name":"https://explore.zoom.us/en/trust/security/security-bulletin/","refsource":"MISC","tags":[],"title":"Security Bulletins | Zoom","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-22788","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22788","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Reported by James Tsz Ko Yeung","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"22788","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"meetings","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"22788","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zoom","cpe5":"rooms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-22788","qid":"377687","title":"Zoom Client for Meetings Multiple Security Vulnerabilities (ZSB- 22010)"},{"cve":"CVE-2022-22788","qid":"377706","title":"Zoom Rooms for Conference Room DLL Injection Vulnerability (ZSB- 22010)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@zoom.us","DATE_PUBLIC":"2022-06-14T12:00:00.000Z","ID":"CVE-2022-22788","STATE":"PUBLIC","TITLE":"DLL injection in Zoom Opener installer for Zoom and Zoom Rooms clients"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Zoom Client for Meetings","version":{"version_data":[{"version_affected":"<","version_value":"5.10.3"}]}},{"product_name":"All Zoom Rooms for Conference Room for Windows","version":{"version_data":[{"version_affected":"<","version_value":"5.10.3"}]}}]},"vendor_name":"Zoom Video Communications Inc"}]}},"credit":[{"lang":"eng","value":"Reported by James Tsz Ko Yeung"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Uncontrolled Search Path Element"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://explore.zoom.us/en/trust/security/security-bulletin/","name":"https://explore.zoom.us/en/trust/security/security-bulletin/"}]},"source":{"discovery":"USER"}},"nvd":{"publishedDate":"2022-06-15 21:15:00","lastModifiedDate":"2022-06-27 17:54:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":6.9},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*","versionEndExcluding":"5.10.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*","versionEndExcluding":"5.10.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"22788","Ordinal":"225242","Title":"CVE-2022-22788","CVE":"CVE-2022-22788","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"22788","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}