CVE-2022-28763

EUVD-2022-33202
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ZoomCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
zoommeetings
𝑥
< 5.12.2
zoommeetings
𝑥
< 5.12.2
zoommeetings
𝑥
< 5.12.2
zoomrooms_for_conference_rooms
𝑥
< 5.12.2
zoomrooms_for_conference_rooms
𝑥
< 5.12.2
zoomrooms_for_conference_rooms
𝑥
< 5.12.2
zoomvirtual_desktop_infrastructure
𝑥
< 5.12.2
𝑥
= Vulnerable software versions