Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22788

Опубликовано: 15 июн. 2022
Источник: nvd
CVSS3: 7.1
CVSS3: 7.8
CVSS2: 6.9
EPSS Низкий

Описание

The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*
Версия до 5.10.3 (исключая)
cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*
Версия до 5.10.3 (исключая)

EPSS

Процентиль: 69%
0.00613
Низкий

7.1 High

CVSS3

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.

EPSS

Процентиль: 69%
0.00613
Низкий

7.1 High

CVSS3

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-427