The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://explore.zoom.us/en/trust/security/security-bulletin/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Zoom
Published: 2022-08-11T14:55:46.515107Z
Updated: 2024-09-17T02:53:24.397Z
Reserved: 2022-04-06T00:00:00
Link: CVE-2022-28755
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-11T15:15:12.357
Modified: 2024-11-21T06:57:52.257
Link: CVE-2022-28755
Redhat
No data.