First published: Tue Jun 14 2022(Updated: )
The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.10.3 | |
Zoom Rooms | <5.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22788 is a vulnerability in the Zoom Client for Meetings and Zoom Rooms for Windows that allows the download of the Zoom Opener installer when attempting to join a meeting without the Zoom Meeting Client installed.
CVE-2022-22788 can allow attackers to download malicious Zoom Opener installer when users try to join meetings without having the Zoom Meeting Client installed, potentially leading to compromise of the user's system.
Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are affected by CVE-2022-22788.
CVE-2022-22788 has a severity value of 7.8, which is considered high.
To fix CVE-2022-22788, update your Zoom Client for Meetings and Zoom Rooms for Windows to version 5.10.3 or later.