7.5

CVE-2022-22787

Insufficient hostname validation during Clusterswitch message in Zoom Client for Meetings

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting users client to connect to a malicious server when attempting to use Zoom services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meetings SwPlatform android Version < 5.10.0
Zoom ≫ Meetings SwPlatform iphone_os Version < 5.10.0
Zoom ≫ Meetings SwPlatform linux Version < 5.10.0
Zoom ≫ Meetings SwPlatform macos Version < 5.10.0
Zoom ≫ Meetings SwPlatform windows Version < 5.10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.63% 0.884
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
security@zoom.us 5.9 1.6 4.2
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://explore.zoom.us/en/trust/security/security-bulletin
Vendor Advisory
http://packetstormsecurity.com/files/167238/Zoom-XMPP-Stanza-Smuggling-Remote-Code-Execution.html
Third Party Advisory
VDB Entry