CVE-2022-28766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
17/11/2022
Last modified:
22/11/2022

Description

Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability to run arbitrary code in the context of the Zoom client.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:* 5.12.6 (excluding)
cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* 5.12.6 (excluding)


References to Advisories, Solutions, and Tools