QID 376640
Date Published: 2022-05-26
QID 376640: Zoom Package Downgrade Vulnerability (ZSB-22008)
Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
Affected Versions:
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.
QID Detection Logic (Authenticated):
This authenticated QID detects vulnerable Zoom Client and Zoom Rooms version
This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.
CVEs related to QID 376640
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-22008 |
|