cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-42441,https://securityvulnerability.io/vulnerability/CVE-2024-42441,Zoom Workplace Desktop App for macOS: Privilege Escalation Vulnerability,"Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.",Zoom,"Zoom Workplace Desktop App For Mac OS, Zoom Meeting Sdk For Mac OS, Zoom Rooms Client For Mac OS",6.7,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-42439,https://securityvulnerability.io/vulnerability/CVE-2024-42439,Privilege Escalation Vulnerability in macOS Workplace Desktop App,Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.,Zoom,Zoom Workplace Desktop App For Mac OS And Zoom Meeting Sdk For Mac OS,6.5,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-08-14T17:15:00.000Z,0 CVE-2024-39820,https://securityvulnerability.io/vulnerability/CVE-2024-39820,Uncontrolled Search Path Element in Installer May Cause Denial of Service via Local Access,Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.,"Zoom Communications, Inc",Zoom Workplace Desktop App For Mac OS,6.6,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-07-15T18:15:00.000Z,0 CVE-2024-27247,https://securityvulnerability.io/vulnerability/CVE-2024-27247,Privilege Escalation Vulnerability in Zoom Desktop Client for macOS,Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.,Zoom,Zoom Desktop Client For Mac OS,5.5,MEDIUM,0.0004299999854993075,false,false,false,false,,false,false,2024-04-09T17:15:27.531Z,0 CVE-2023-43591,https://securityvulnerability.io/vulnerability/CVE-2023-43591,Improper Privilege Management in Zoom Rooms for macOS,"An improper privilege management flaw exists in Zoom Rooms for macOS that may enable an authenticated user to escalate privileges after gaining local access. This vulnerability affects all versions prior to 5.16.0, posing potential risks to system integrity and confidentiality. It is crucial for users to update to the latest version to mitigate this risk.","Zoom Video Communications, Inc.",Zoom Rooms For Mac OS,7.8,HIGH,0.0004299999854993075,false,false,false,false,,false,false,2023-11-15T00:15:00.000Z,0 CVE-2023-43590,https://securityvulnerability.io/vulnerability/CVE-2023-43590,Privilege Escalation Vulnerability in Zoom Rooms for macOS,"A vulnerability in Zoom Rooms for macOS, present in versions prior to 5.16.0, allows an authenticated user to perform privilege escalation following local access. This could enable malicious users to gain elevated permissions and potentially alter system configurations or access sensitive information within the compromised system. Users are strongly advised to update to the latest version to mitigate any risks associated with this vulnerability.","Zoom Video Communications, Inc.",Zoom Rooms For Mac OS,7.8,HIGH,0.0004299999854993075,false,false,false,false,,false,false,2023-11-15T00:15:00.000Z,0 CVE-2023-28600,https://securityvulnerability.io/vulnerability/CVE-2023-28600,,Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.,"Zoom Video Communications, Inc.",Zoom For Mac OS Client,5.4,MEDIUM,0.0005300000193528831,false,false,false,false,,false,false,2023-06-13T18:15:00.000Z,0 CVE-2023-28599,https://securityvulnerability.io/vulnerability/CVE-2023-28599,,Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.,"Zoom Video Communications, Inc.","Zoom For Android,Zoom For iOS,Zoom For Linux,Zoom For Mac OS,Zoom For Windows",4.3,MEDIUM,0.0005600000149570405,false,false,false,false,,false,false,2023-06-13T17:15:00.000Z,0 CVE-2022-36925,https://securityvulnerability.io/vulnerability/CVE-2022-36925,Insecure key generation for Zoom Rooms for macOS Clients,Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service.,Zoom,Zoom Rooms For Mac OS,4.4,MEDIUM,0.0004199999966658652,false,false,false,false,,false,false,2023-01-09T00:00:00.000Z,0 CVE-2022-36927,https://securityvulnerability.io/vulnerability/CVE-2022-36927,Local Privilege Escalation in Zoom Rooms for macOS Clients,"A local privilege escalation vulnerability exists in Zoom Rooms for macOS clients prior to version 5.11.3. This flaw allows a low-privileged user to exploit the vulnerability and escalate their privileges to root, potentially compromising the system's security.",Zoom,Zoom Rooms For Mac OS,8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2023-01-09T00:00:00.000Z,0 CVE-2022-36926,https://securityvulnerability.io/vulnerability/CVE-2022-36926,Local Privilege Escalation in Zoom Rooms for macOS Clients,"A vulnerability exists in Zoom Rooms for macOS prior to version 5.11.3, which allows a low-privileged local user to escalate their privileges to root. This exploitation could lead to unauthorized access and potential manipulation of system controls, highlighting the need for timely updating and patch management strategies.",Zoom,Zoom Rooms For Mac OS,8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2023-01-09T00:00:00.000Z,0 CVE-2022-28768,https://securityvulnerability.io/vulnerability/CVE-2022-28768,Local Privilege Escalation in Zoom Client Installer for macOS,The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.,Zoom,Zoom Client For Meetings Installer For Mac OS (standard And For It Admin),8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2022-11-17T23:15:00.000Z,0 CVE-2022-28764,https://securityvulnerability.io/vulnerability/CVE-2022-28764,Local information exposure in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients,Zoom Rooms For Conference Room (for Android, iOS, Linux, Mac OS, And Windows)",3.3,LOW,0.0004199999966658652,false,false,false,false,,false,false,2022-11-14T21:15:00.000Z,0 CVE-2022-28763,https://securityvulnerability.io/vulnerability/CVE-2022-28763,Improper URL parsing in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients,Zoom Rooms For Conference Room (for Android, iOS, Linux, Mac OS, And Windows)",8.8,HIGH,0.001970000099390745,false,false,false,false,,false,false,2022-10-31T20:15:00.000Z,0 CVE-2022-28762,https://securityvulnerability.io/vulnerability/CVE-2022-28762,Debugging port misconfiguration in Zoom Apps in the Zoom Client for Meetings for macOS,"Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running certain Zoom Apps, a local debugging port is opened by the Zoom client. A local malicious user could use this debugging port to connect to and control the Zoom Apps running in the Zoom client.",Zoom,Zoom Client For Meetings For Mac OS,7.3,HIGH,0.0004400000034365803,false,false,false,false,,false,false,2022-10-14T15:15:00.000Z,0 CVE-2022-28757,https://securityvulnerability.io/vulnerability/CVE-2022-28757,Local Privilege Escalation in Auto Updater for Zoom Client for Meetings for macOS,The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.,Zoom,Zoom Client For Meetings For Mac OS,8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2022-08-18T20:15:00.000Z,0 CVE-2022-28751,https://securityvulnerability.io/vulnerability/CVE-2022-28751,Local Privilege Escalation in Zoom Client for Meetings for MacOS,The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.,Zoom,Zoom Client For Meetings For Mac OS,8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2022-08-17T22:15:00.000Z,0 CVE-2022-28756,https://securityvulnerability.io/vulnerability/CVE-2022-28756,Local Privilege Escalation in Auto Updater for Zoom Client for Meetings for macOS,The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.,Zoom,Zoom Client For Meetings For Mac OS,8.8,HIGH,0.0004199999966658652,false,false,false,false,,false,false,2022-08-15T23:15:00.000Z,0 CVE-2022-28755,https://securityvulnerability.io/vulnerability/CVE-2022-28755,Improper URL parsing in Zoom Clients,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.",Zoom,"Zoom Client For Meetings (for Android, iOS, Linux, Mac OS, And Windows),Zoom Vdi Windows Meeting Clients",9.6,CRITICAL,0.001120000029914081,false,false,false,false,,false,false,2022-08-11T15:15:00.000Z,0 CVE-2022-22787,https://securityvulnerability.io/vulnerability/CVE-2022-22787,Insufficient hostname validation during Clusterswitch message in Zoom Client for Meetings,"The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting users client to connect to a malicious server when attempting to use Zoom services.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",5.9,MEDIUM,0.0013000000035390258,false,false,false,false,,false,false,2022-05-18T17:15:00.000Z,0 CVE-2022-22785,https://securityvulnerability.io/vulnerability/CVE-2022-22785,Improperly constrained session cookies in Zoom Client for Meetings,"The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",5.9,MEDIUM,0.0015200000489130616,false,false,false,false,,false,false,2022-05-18T16:15:00.000Z,0 CVE-2022-22784,https://securityvulnerability.io/vulnerability/CVE-2022-22784,Improper XML Parsing in Zoom Client for Meetings,"The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the receiving users client perform a variety of actions.This issue could be used in a more sophisticated attack to forge XMPP messages from the server.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",8.1,HIGH,0.0006500000017695129,false,false,false,false,,false,false,2022-05-18T16:15:00.000Z,0 CVE-2022-22781,https://securityvulnerability.io/vulnerability/CVE-2022-22781,Update package downgrade in Zoom Client for Meetings for MacOS,The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.,Zoom,Zoom Client For Meetings For Mac OS (standard And For It Admin),7.5,HIGH,0.0008399999933317304,false,false,false,false,,false,false,2022-04-28T15:15:00.000Z,0 CVE-2022-22780,https://securityvulnerability.io/vulnerability/CVE-2022-22780,Zoom Chat Susceptible to Zip Bombing,"The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.6, iOS before version 5.9.0, Linux before version 5.8.6, macOS before version 5.7.3, and Windows before version 5.6.3. This could lead to availability issues on the client host by exhausting system resources.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",4.7,MEDIUM,0.0009699999936856329,false,false,false,false,,false,false,2022-02-09T23:15:00.000Z,0 CVE-2021-34425,https://securityvulnerability.io/vulnerability/CVE-2021-34425,Server Side Request Forgery in Zoom Client for Meetings chat,"The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat\'s ""link preview"" functionality. In versions prior to 5.7.3, if a user were to enable the chat\'s ""link preview"" feature, a malicious actor could trick the user into potentially sending arbitrary HTTP GET requests to URLs that the actor cannot reach directly.",Zoom,"Zoom Client For Meetings For Android,Zoom Client For Meetings For iOS,Zoom Client For Meetings For Linux,Zoom Client For Meetings For Mac OS,Zoom Client For Meetings For Windows",4.7,MEDIUM,0.0007800000021234155,false,false,false,false,,false,false,2021-12-14T00:00:00.000Z,0