Update package downgrade in Zoom Client for Meetings for MacOS
Vulnerability Description
The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22781
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Patrick Wardle of Objective-See
More from Zoom Video Communications Inc
View All →Affected Vendor
Zoom Video Communications Inc
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.