CVE-2022-22781

Description

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting users currently installed version to a less secure version.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.112

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-34423,CVE-2021-34424,CVE-2022-22781,CVE-2022-22782,CVE-2022-22786 are affected in Zoom 5.8.0Windows
Vulnerabilities CVE-2021-34423,CVE-2021-34424,CVE-2022-22781,CVE-2022-22782,CVE-2022-22786 are affected in Zoom 5.8.0(x64)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-321880Zoom (5.8.1.1435)
PATCH-319772Zoom (x64) (5.6.6.961)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234