CVE-2022-22786: Update package downgrade in Zoom Client for Meetings for Windows
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a user into downgrading their Zoom client to a less secure version.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22786?
CVE-2022-22786 is a vulnerability in the Zoom Client for Meetings and Zoom Rooms for Conference Room for Windows that allows an attacker to trick a user into downgrading the software during the update process.
How does CVE-2022-22786 affect Zoom?
CVE-2022-22786 affects Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0.
What is the severity of CVE-2022-22786?
CVE-2022-22786 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2022-22786?
An attacker can exploit CVE-2022-22786 by tricking a user into downgrading the Zoom software during the update process.
Is there a fix for CVE-2022-22786?
Yes, the fix for CVE-2022-22786 is to update the Zoom Client for Meetings and Zoom Rooms for Conference Room for Windows to version 5.10.0 or later.