CVE-2022-36928: Path Traversal in Zoom for Android Clients
Published Jan 9, 2023
·Updated
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.
Affected Software
1 affected component
Zoom Zoom Android<5.13.0
Event History
Jan 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-36928?
CVE-2022-36928 is a path traversal vulnerability in Zoom for Android clients before version 5.13.0.
2
How can a third party app exploit CVE-2022-36928?
A third party app can exploit CVE-2022-36928 by reading and writing to the Zoom application data directory.
3
What is the severity of CVE-2022-36928?
The severity of CVE-2022-36928 is high with a CVSS score of 7.1.
4
Which version of Zoom for Android is affected by CVE-2022-36928?
Zoom for Android clients before version 5.13.0 are affected by CVE-2022-36928.
5
How do I fix CVE-2022-36928?
To fix CVE-2022-36928, update your Zoom for Android client to version 5.13.0 or later.