Rapid7 Vulnerability & Exploit Database

Zoom: CVE-2022-22786: Update package downgrade in Zoom Client for Meetings for Windows

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Zoom: CVE-2022-22786: Update package downgrade in Zoom Client for Meetings for Windows

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
05/17/2022
Created
04/01/2023
Added
03/22/2023
Modified
04/03/2023

Description

The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.

Solution(s)

  • zoom-upgrade-to-latest

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;