Zoom Client是美国Zoom公司的一款支持多种平台的视频会议客户端应用程序。 Zoom Client for Meetings 5.10.0之前版本存在安全漏洞,该漏洞源于无法正确解析 XMPP 消息中的 XML。攻击者利用该漏洞突破当前 XMPP 环境并创建新的环境让受害者的客户端执行各种操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Video Communications Inc | Zoom Client for Meetings for Android | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for iOS | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for Linux | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for MacOS | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for Windows | unspecified ~ 5.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-22786 | 7.5 HIGH | Update package downgrade in Zoom Client for Meetings for Windows |
| CVE-2022-22785 | 5.9 MEDIUM | Improperly constrained session cookies in Zoom Client for Meetings |
| CVE-2022-22787 | 5.9 MEDIUM | Insufficient hostname validation during Clusterswitch message in Zoom Client for Meetings |
No comments yet