vulnerability

Zoom: CVE-2022-22787: Insufficient hostname validation during server switch in Zoom Client for Meetings

Severity
6
CVSS
(AV:N/AC:H/Au:S/C:C/I:N/A:P)
Published
May 17, 2022
Added
Nov 14, 2023
Modified
Jan 8, 2025

Description

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting user's client to connect to a malicious server when attempting to use Zoom services.

Solution

zoom-zoom-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.