CVE-2022-22785
Estado: ModificadaCrítica (9.1)—
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 9.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.46%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-565
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-22785",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@zoom.us",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@zoom.us",
"affectedData": [
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Client for Meetings for Android",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.10.0",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Client for Meetings for iOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.10.0",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Client for Meetings for Linux",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.10.0",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Client for Meetings for MacOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.10.0",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Client for Meetings for Windows",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.10.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-05-18T16:15:08.697",
"references": [
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin",
"tags": [
"Vendor Advisory"
],
"source": "security@zoom.us"
},
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-565"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user."
},
{
"lang": "es",
"value": "Zoom Client for Meetings (para Android, iOS, Linux, MacOS y Windows) versiones anteriores a 5.10.0, no restringe apropiadamente las cookies de sesión del cliente a los dominios de Zoom. Este problema podría ser usado en un ataque más sofisticado para enviar a un usuario desprevenido las cookies de sesión de Zoom a un dominio que no es de Zoom. Esto podría permitir la suplantación de un usuario de Zoom"
}
],
"lastModified": "2026-06-17T04:29:02.357",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "257325E7-C897-49A8-8F82-7AF256A356C5",
"versionEndExcluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "E22CE428-4C2A-4D98-A05C-0DC947511A82",
"versionEndExcluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "BB3D750A-6070-43B9-8D2F-0BF840FAEAAE",
"versionEndExcluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "AD42820E-D045-4AE0-8A35-9B4E3007B71A",
"versionEndExcluding": "5.10.0"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "DDF53A4B-7533-4DDA-9BEF-C803127FEDDD",
"versionEndExcluding": "5.10.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@zoom.us"
}