Rapid7

vulnerability

Zoom Zoom: CVE-2022-22787: Insufficient hostname validation during server switch in Zoom Client for Meetings

Severity
6
CVSS
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
Published
May 17, 2022
Added
Nov 14, 2023
Modified
Mar 25, 2026

Description

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting user’s client to connect to a malicious server when attempting to use Zoom services.

Solution

zoom-zoom-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.