CRITICAL🇵🇱 Wersja polska

CVE-2022-28755

CVSS 9.6v3.1pub. 2022-08-11upd. 2024-11-21

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Zoom Virtual Desktop Infrastructure

    APP
    Zoom
    < 5.10.7
  • Zoom

    APP
    Zoom
    < 5.11.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-24691CRITICAL9.6PL ✓same product

Privilege escalation w Zoom Desktop Client, VDI Client i Meeting SDK dla Windows

CVE-2023-39213CRITICAL9.6PL ✓same product

Zoom Desktop Client i VDI Client — privilege escalation przez sieć

CVE-2023-39216CRITICAL9.6PL ✓same product

Nieprawidłowa walidacja danych wejściowych w Zoom Desktop Client dla Windows — privilege escalation

CVE-2023-36534CRITICAL9.3PL ✓same product

Path traversal w Zoom Desktop Client dla Windows — eskalacja uprawnień

CVE-2021-34423CRITICAL9.8PL ✓same product

Buffer overflow w produktach Zoom umożliwiający RCE lub crash usługi