Vulnerability Description
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zoom | Meetings | < 5.10.0 |
Related Weaknesses (CWE)
References
- https://explore.zoom.us/en/trust/security/security-bulletinVendor Advisory
- https://explore.zoom.us/en/trust/security/security-bulletinVendor Advisory
FAQ
What is CVE-2022-22784?
CVE-2022-22784 is a vulnerability with a CVSS score of 8.1 (HIGH). The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of ...
How severe is CVE-2022-22784?
CVE-2022-22784 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22784?
Check the references section above for vendor advisories and patch information. Affected products include: Zoom Meetings.