9.1

CVE-2022-22785

Improperly constrained session cookies in Zoom Client for Meetings

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meetings SwPlatform android Version < 5.10.0
Zoom ≫ Meetings SwPlatform iphone_os Version < 5.10.0
Zoom ≫ Meetings SwPlatform linux Version < 5.10.0
Zoom ≫ Meetings SwPlatform macos Version < 5.10.0
Zoom ≫ Meetings SwPlatform windows Version < 5.10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.46% 0.879
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
security@zoom.us 5.9 1.6 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L
CWE-565 Reliance on Cookies without Validation and Integrity Checking

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

https://explore.zoom.us/en/trust/security/security-bulletin
Vendor Advisory