TROYANOSYVIRUS
Back to CVEs

CVE-2022-22782

HIGH
7.9

Description

The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue during the installer repair operation. A malicious actor could utilize this to potentially delete system level files or folders, causing integrity or availability issues on the user’s host machine.

CVE Details

CVSS v3.1 Score7.9
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
Published4/28/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

zoom:meetingszoom:rooms_for_conference_roomszoom:vdi_windows_meeting_clientszoom:zoom_plugin_for_microsoft_outlook

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.