First published: Thu Nov 17 2022(Updated: )
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meetings | <5.12.6 | |
Zoom Rooms | <5.12.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-28766.
The affected software for this vulnerability are Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6.
The severity of CVE-2022-28766 is high with a severity value of 7.3.
A local low-privileged user can exploit CVE-2022-28766 to run arbitrary code in the context of the Zoom client.
You can find more information about CVE-2022-28766 in the security bulletin on the Zoom website: [https://explore.zoom.us/en/trust/security/security-bulletin/](https://explore.zoom.us/en/trust/security/security-bulletin/)