CVE-2022-22780
Published Feb 9, 2022
Last updated 3 years ago
Overview
- Description
- The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources.
- Source
- security@zoom.us
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
- nvd@nist.gov
- CWE-400
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "CC39A599-FC9F-4969-9CC7-71FE55025C08", "versionEndExcluding": "5.6.3" }, { "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:*", "vulnerable": true, "matchCriteriaId": "1605E28D-0488-49DA-9098-010813523159", "versionEndExcluding": "5.7.3" }, { "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "97D6B6D9-A656-4D2C-A627-1766206644B8", "versionEndExcluding": "5.8.6" }, { "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:linux:*:*", "vulnerable": true, "matchCriteriaId": "55F568FB-8385-46CC-9C22-EA55E0019B34", "versionEndExcluding": "5.8.6" }, { "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:iphone_os:*:*", "vulnerable": true, "matchCriteriaId": "1FE37907-1E61-4341-8302-941E50B192DB", "versionEndExcluding": "5.9.0" } ], "operator": "OR" } ] } ]