9.6

CVE-2022-28763

Improper URL parsing in Zoom Clients

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zoom ≫ Meetings SwPlatform android Version < 5.12.2
Zoom ≫ Meetings SwPlatform iphone_os Version < 5.12.2
Zoom ≫ Meetings SwPlatform linux Version < 5.12.2
Zoom ≫ Meetings SwPlatform macos Version < 5.12.2
Zoom ≫ Meetings SwPlatform windows Version < 5.12.2
Zoom ≫ Rooms For Conference Rooms SwPlatform android Version < 5.12.2
Zoom ≫ Rooms For Conference Rooms SwPlatform iphone_os Version < 5.12.2
Zoom ≫ Rooms For Conference Rooms SwPlatform linux Version < 5.12.2
Zoom ≫ Rooms For Conference Rooms SwPlatform macos Version < 5.12.2
Zoom ≫ Rooms For Conference Rooms SwPlatform windows Version < 5.12.2
Zoom ≫ Virtual Desktop Infrastructure SwPlatform windows Version < 5.12.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.644
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.6 2.8 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
security@zoom.us 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://explore.zoom.us/en/trust/security/security-bulletin/
Vendor Advisory