CVE-2022-28763: Improper URL parsing in Zoom Clients
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Zoom vulnerability?
The vulnerability ID for this Zoom vulnerability is CVE-2022-28763.
What is the severity of CVE-2022-28763?
The severity of CVE-2022-28763 is critical, with a severity value of 9.6.
Which software versions are affected by CVE-2022-28763?
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2, as well as Zoom Rooms for Conference Rooms and Zoom Virtual Desktop Infrastructure, are affected by CVE-2022-28763.
What is the impact of CVE-2022-28763?
CVE-2022-28763 allows a malicious Zoom meeting URL to direct users to connect to an arbitrary network address, leading to additional attacks.
Is there a fix available for CVE-2022-28763?
Yes, the fix for CVE-2022-28763 is to update Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) to version 5.12.2 or later.