// For flags

CVE-2022-22784

Improper XML Parsing in Zoom Client for Meetings

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.

Zoom Client for Meetings (para Android, iOS, Linux, MacOS y Windows) versiones anteriores a 5.10.0, no analizaba apropiadamente las estrofas XML en los mensajes XMPP. Esto puede permitir a un usuario malicioso salir del contexto actual del mensaje XMPP y crear un nuevo contexto de mensaje para que el cliente de usuarios receptores lleve a cabo una variedad de acciones. Este problema podría ser usado en un ataque más sofisticado para falsificar mensajes XMPP desde el servidor

*Credits: Ivan Fratric of Google Project Zero
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-01-07 CVE Reserved
  • 2022-05-18 CVE Published
  • 2023-12-09 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-91: XML Injection (aka Blind XPath Injection)
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.10.0
Search vendor "Zoom" for product "Meetings" and version " < 5.10.0"
android
Affected
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.10.0
Search vendor "Zoom" for product "Meetings" and version " < 5.10.0"
iphone_os
Affected
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.10.0
Search vendor "Zoom" for product "Meetings" and version " < 5.10.0"
linux
Affected
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.10.0
Search vendor "Zoom" for product "Meetings" and version " < 5.10.0"
macos
Affected
Zoom
Search vendor "Zoom"
Meetings
Search vendor "Zoom" for product "Meetings"
< 5.10.0
Search vendor "Zoom" for product "Meetings" and version " < 5.10.0"
windows
Affected