Zoom Client是美国Zoom公司的一款支持多种平台的视频会议客户端应用程序。 Zoom Client for Meetings 5.10.0之前版本存在信息泄露漏洞,该漏洞源于无法将客户端会话 cookie 正确约束到 Zoom 域。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zoom Video Communications Inc | Zoom Client for Meetings for Android | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for iOS | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for Linux | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for MacOS | unspecified ~ 5.10.0 | - |
|
| Zoom Video Communications Inc | Zoom Client for Meetings for Windows | unspecified ~ 5.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-22784 | 8.1 HIGH | Improper XML Parsing in Zoom Client for Meetings |
| CVE-2022-22786 | 7.5 HIGH | Update package downgrade in Zoom Client for Meetings for Windows |
| CVE-2022-22787 | 5.9 MEDIUM | Insufficient hostname validation during Clusterswitch message in Zoom Client for Meetings |
No comments yet