CVE-2022-22787 describes a hostname validation vulnerability in Zoom Client for Meetings across Android, iOS, Linux, macOS, and Windows versions prior to 5.10.0. This flaw, rated 7.5 HIGH CVSS, could allow an attacker to redirect a user's client to a malicious server during a server switch, potentially leading to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation is confirmed, the vulnerability has garnered significant community discussion and media attention, indicating its potential for sophisticated attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.10.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:* | ||
< 5.10.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:iphone_os:*:* | ||
< 5.10.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:linux:*:* | ||
< 5.10.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:* | ||
< 5.10.0CPE matchmatch criteria | cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.