Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-33205 Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2025-04-29T19:37:26.893Z

Reserved: 2022-04-06T00:00:00.000Z

Link: CVE-2022-28766

cve-icon Vulnrichment

Updated: 2024-08-03T06:03:52.736Z

cve-icon NVD

Status : Modified

Published: 2022-11-17T23:15:15.007

Modified: 2024-11-21T06:57:53.587

Link: CVE-2022-28766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.