CVE-2022-22785: Improperly constrained session cookies in Zoom Client for Meetings
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22785?
CVE-2022-22785 is a vulnerability in the Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 that allows an attacker to send session cookies to a non-Zoom domain.
How does CVE-2022-22785 affect Zoom users?
CVE-2022-22785 affects Zoom users by exposing their session cookies to potential exploitation by attackers.
What is the severity of CVE-2022-22785?
CVE-2022-22785 has a severity rating of 9.1 (Critical).
How can I mitigate CVE-2022-22785?
To mitigate CVE-2022-22785, users should update to Zoom Client for Meetings version 5.10.0 or later.
Where can I find more information about CVE-2022-22785?
You can find more information about CVE-2022-22785 in the Zoom security bulletin at https://explore.zoom.us/en/trust/security/security-bulletin.