Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-678v-qchw-37jr

Опубликовано: 19 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.

EPSS

Процентиль: 56%
0.00331
Низкий

8.8 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.

CVSS3: 7.5
fstec
около 4 лет назад

Уязвимость программного обеспечения для проведения видеоконференций Zoom для Windows, связанная с некорректной проверкой текущей установленной версии программного обеспечения при обновлении, позволяющая нарушителю обойти определенные ограничения безопасности

EPSS

Процентиль: 56%
0.00331
Низкий

8.8 High

CVSS3

Дефекты

CWE-494