#VU66376 Input validation error in Zoom Video Communications, Inc. products - CVE-2022-28755 

 

#VU66376 Input validation error in Zoom Video Communications, Inc. products - CVE-2022-28755

Published: August 10, 2022 / Updated: August 27, 2022


Vulnerability identifier: #VU66376
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-28755
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Virtual Desktop Infrastructure (VDI)
Zoom Workplace App for Android
Zoom Workplace App for iOS
Software vendor:
Zoom Video Communications, Inc.

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when parsing meeting URL. A remote attacker can trick the victim to follow a specially crafted URL, which can direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.


Remediation

Install updates from vendor's website.

External links