CVE-2022-28763

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ZoomCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
zoommeetings
𝑥
< 5.12.2
zoommeetings
𝑥
< 5.12.2
zoommeetings
𝑥
< 5.12.2
zoomrooms_for_conference_rooms
𝑥
< 5.12.2
zoomrooms_for_conference_rooms
𝑥
< 5.12.2
zoomrooms_for_conference_rooms
𝑥
< 5.12.2
zoomvirtual_desktop_infrastructure
𝑥
< 5.12.2
𝑥
= Vulnerable software versions