CVE detail
CVE-2022-22786
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
Security flaws in Zoom can be exploited to compromise another user over chat by sending specially crafted messages. A set of four security flaws in the popular video conferencing service Zoom could be exploited to compromise another user over chat by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages.Tracked from CVE-2022-22784 through CVE-2022-22787, […]
newssecurityaffairs.comMay 25, 2022, 11:12 AMGoogle’s Project Zero has disclosed the details of a zero-click remote code execution exploit targeting the Zoom video conferencing software.
newswww.securityweek.comMay 25, 2022, 10:37 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-39819CVSS 6.7 · Medium
Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
- CVE-2023-43582CVSS 5.5 · Medium
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
- CVE-2023-39206CVSS 3.7 · Low
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- CVE-2023-39204CVSS 4.3 · Medium
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.
- CVE-2023-39199CVSS 4.9 · Medium
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.
- CVE-2023-36539CVSS 5.3 · Medium
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.