vulnerability
Zoom: CVE-2022-22787: Insufficient hostname validation during server switch in Zoom Client for Meetings
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:H/Au:S/C:C/I:N/A:P) | May 17, 2022 | Nov 14, 2023 | Jan 8, 2025 |
Severity
6
CVSS
(AV:N/AC:H/Au:S/C:C/I:N/A:P)
Published
May 17, 2022
Added
Nov 14, 2023
Modified
Jan 8, 2025
Description
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting user's client to connect to a malicious server when attempting to use Zoom services.
Solution
zoom-zoom-upgrade-latest

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.