← Back to CVEs
CVE-2022-22782
HIGH7.9
Description
The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the user’s host machine.
CVE Details
CVSS v3.1 Score7.9
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published4/28/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
zoom:meetingszoom:rooms_for_conference_roomszoom:vdi_windows_meeting_clientszoom:zoom_plugin_for_microsoft_outlook
References
https://explore.zoom.us/en/trust/security/security-bulletin/(security@zoom.us)
https://explore.zoom.us/en/trust/security/security-bulletin/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.