CVE-2022-28764
Estado: ModificadaBaja (3.3)—
The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-200
- CWE-459
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-28764",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-28764",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-29T19:19:17.362470Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@zoom.us",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@zoom.us",
"affectedData": [
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.12.6",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom VDI Windows Meeting Clients",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.12.6",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Zoom Rooms for Conference Room (for Android, iOS, Linux, macOS, and Windows)",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.12.6",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-11-14T21:15:13.123",
"references": [
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
"tags": [
"Vendor Advisory"
],
"source": "security@zoom.us"
},
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@zoom.us",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-459"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account."
},
{
"lang": "es",
"value": "Zoom Client para reuniones (para Android, iOS, Linux, macOS y Windows) anterior a la versión 5.12.6 es susceptible a una vulnerabilidad de exposición de información local. Si no se borran los datos de una base de datos SQL local después de finalizar una reunión y el uso de una clave por dispositivo insuficientemente segura que cifra esa base de datos da como resultado que un usuario malicioso local pueda obtener información de la reunión, como el chat de la reunión anterior atendido desde esa cuenta de usuario local."
}
],
"lastModified": "2026-06-17T04:38:59.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "9A4FFD8B-AAFF-4187-9603-303E045ABBC6",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "AC5B36F0-62C9-45F9-A446-06302517C430",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "B1211D7C-9D7D-48D2-919E-CE69816BB5BC",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "CA075C4F-52CB-45DB-8FC3-9E09D748A9A7",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "797ADEB2-DBD7-4437-97CE-FB3AC472708D",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "6C49EC7B-3A03-451C-BBC4-CBD1AE555A78",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "4F725CBC-7382-46DB-A369-C7DE4F7BC260",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "7DF05B3E-5E82-4296-A9C9-6545333C7C18",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*",
"vulnerable": true,
"matchCriteriaId": "8C098940-2C55-4183-AFEC-A30423DF5EA4",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "D65A2943-960F-4652-A8F3-17764952C530",
"versionEndExcluding": "5.12.6"
},
{
"criteria": "cpe:2.3:a:zoom:vdi_windows_meeting_clients:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "37E75456-2466-481D-9675-6E8E1D57B147",
"versionEndExcluding": "5.12.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@zoom.us"
}