QID 377783
Date Published: 2022-11-22
QID 377783: Zoom VDI DLL Injection Vulnerability (ZSB-22027)
Zoom provides video communications with a cloud platform for video and audio conferencing, chat, and webinars across mobile, desktop, and room systems.
CVE-2022-28766: A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.
Affected Versions:
Zoom VDI Windows Meeting Client for Windows (32-bit) prior to 5.12.6
QID Detection Logic:
This authenticated QID detects vulnerable Zoom VDI Windows Meeting Clients prior to version 5.12.6 on Windows
Successful exploitation of this vulnerability may allow local attacker to run malicious code using the context of a legitimate process and gains several advantages, especially the ability to access the processes memory and permissions.
CVEs related to QID 377783
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZSB-22027 |
|