7.1

CVE-2022-22782

Local privilege escalation in Windows Zoom Clients

The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the user’s host machine.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meetings SwPlatform windows Version < 5.9.7
Zoom ≫ Rooms For Conference Rooms SwPlatform windows Version < 5.10.0
Zoom ≫ Vdi Windows Meeting Clients Version < 5.9.6
Zoom ≫ Zoom Plugin For Microsoft Outlook SwPlatform windows Version < 5.10.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.286
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
NIST 6.6 3.9 9.2
AV:L/AC:L/Au:N/C:N/I:C/A:C
security@zoom.us 7.9 1.5 5.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://explore.zoom.us/en/trust/security/security-bulletin/
Vendor Advisory