Meetings
Vendor:
First CVE: Apr 1, 2020 · Active for 6 years
37
Total CVEs
More Total CVEs than 98% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Meetings over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2020
6 years ago
Most Recent CVE
Nov 15, 2023
986 days ago
CVE Severity & Scoring
Meetings37 CVEs
14%
70%
11%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (43.2%)
Network21 (56.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None31 (83.8%)
Unknown0 (0.0%)
Required6 (16.2%)
Privileges Required
Low21 (56.8%)
High0 (0.0%)
None16 (43.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34423CRITICAL A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackber | Nov 24, 2021 | 9.8 | 34 | NO | NO |
CVE-2022-22785CRITICAL The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue cou | May 18, 2022 | 9.1 | 30 | NO | NO |
CVE-2021-33907CRITICAL The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of th | Sep 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-22786HIGH The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation versio | May 18, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-22784HIGH The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious u | May 18, 2022 | 8.1 | 28 | NO | NO |
CVE-2022-22788HIGH The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener | Jun 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-22787HIGH The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue | May 18, 2022 | 7.5 | 26 | NO | NO |
CVE-2023-22883HIGH Zoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability i | Mar 16, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-28768HIGH The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user | Nov 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-28762HIGH Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering conte | Oct 14, 2022 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Meetings
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.15.1 | 1 | 7.5 | 0.5% | 0 | 0 |
| 5.15.0 | 1 | 7.5 | 0.5% | 0 | 0 |
| 4.6.11 | 2 | 7.5 | 1.6% | 0 | 0 |