SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22781

This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

HIGH 7.5EPSS 0.42%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
0.42% probability · 36th percentile
CISA KEV
Not listed
Weakness
CWE-354
Affected
zoom/meetings
Source
security@zoom.us

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.