CVE-2022-22782

Description

The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the users host machine.

Risk Information

Base Score
7.1
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
0.126

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-34423,CVE-2021-34424,CVE-2022-22781,CVE-2022-22782,CVE-2022-22786 are affected in Zoom 5.8.0Windows
Vulnerabilities CVE-2021-34423,CVE-2021-34424,CVE-2022-22781,CVE-2022-22782,CVE-2022-22786 are affected in Zoom 5.8.0(x64)Windows
Vulnerabilities CVE-2022-22786,CVE-2022-22782 are fixed in Zoom Rooms (5.15.5.3049)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom (x64) (5.9.7.3931)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom (x64) (5.10.3.4851)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom (x64) (5.9.6.3799)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom (5.9.7.3931)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom (5.10.3.4851)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom Notes Plugin (5.10.3.407)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom Outlook Plugin (5.10.3.406)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom Plugin for Citrix Receiver (5.9.6.20931)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom Client for VDI (5.9.6.20931)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom (5.9.6.3799)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom Plugin for Vmware Horizon Client (5.9.6.20931)Windows
Vulnerabilities CVE-2022-22782 are fixed in Zoom Plugin for Windows Virtual Desktop Client (5.9.6)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-321880Zoom (5.8.1.1435)
PATCH-319772Zoom (x64) (5.6.6.961)
PATCH-331905Zoom Rooms (5.15.5.3049)
PATCH-332244Zoom (x64) (5.15.7.20303)
PATCH-332244Zoom (x64) (5.15.7.20303)
PATCH-332244Zoom (x64) (5.15.7.20303)
PATCH-332243Zoom (5.15.7.20303)
PATCH-332243Zoom (5.15.7.20303)
PATCH-331891Zoom Notes Plugin (5.15.5.925)
PATCH-331892Zoom Outlook Plugin (5.15.5.926)
PATCH-324008Zoom Client for VDI (5.9.6.20931)
PATCH-332243Zoom (5.15.7.20303)
PATCH-324009Zoom Plugin for Citrix Receiver (5.9.6.20931)
PATCH-332248Zoom Plugin for Windows Virtual Desktop Client (5.15.4.23940)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234