HIGH
Improper XML Parsing in Zoom Client for Meetings
Published May 18, 2022
8.1
HIGHCVSS 3.1
EPSS 4.02%
Description
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<5.10.0
- Version
-
- Version unspecifiedStatusaffectedConstraints<5.10.0
- Version
-
- Version unspecifiedStatusaffectedConstraints<5.10.0
- Version
-
- Version unspecifiedStatusaffectedConstraints<5.10.0
- Version
-
- Version unspecifiedStatusaffectedConstraints<5.10.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Zoom Video Communications Inc | Zoom Client for Meetings for Android | n/a |
| ||||||
| Zoom Video Communications Inc | Zoom Client for Meetings for Linux | n/a |
| ||||||
| Zoom Video Communications Inc | Zoom Client for Meetings for MacOS | n/a |
| ||||||
| Zoom Video Communications Inc | Zoom Client for Meetings for Windows | n/a |
| ||||||
| Zoom Video Communications Inc | Zoom Client for Meetings for iOS | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://explore.zoom.us/en/trust/security/security-bulletin x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://explore.zoom.us/en/trust/security/security-bulletin | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zoom
Published May 18, 2022
Updated Sep 16, 2024
Reserved Jan 7, 2022
Link CVE-2022-22784
CISA Vulnrichment
Updated n/a