« Volver al listado

CVE-2022-28764

Estado: ModificadaBaja (3.3)—

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-28764",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-28764",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-29T19:19:17.362470Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zoom.us",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@zoom.us",
      "affectedData": [
        {
          "vendor": "Zoom Video Communications Inc",
          "product": "Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.12.6",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Zoom Video Communications Inc",
          "product": "Zoom VDI Windows Meeting Clients",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.12.6",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Zoom Video Communications Inc",
          "product": "Zoom Rooms for Conference Room (for Android, iOS, Linux, macOS, and Windows)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.12.6",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-11-14T21:15:13.123",
  "references": [
    {
      "url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zoom.us"
    },
    {
      "url": "https://explore.zoom.us/en/trust/security/security-bulletin/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zoom.us",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-459"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account."
    },
    {
      "lang": "es",
      "value": "Zoom Client para reuniones (para Android, iOS, Linux, macOS y Windows) anterior a la versión 5.12.6 es susceptible a una vulnerabilidad de exposición de información local. Si no se borran los datos de una base de datos SQL local después de finalizar una reunión y el uso de una clave por dispositivo insuficientemente segura que cifra esa base de datos da como resultado que un usuario malicioso local pueda obtener información de la reunión, como el chat de la reunión anterior atendido desde esa cuenta de usuario local."
    }
  ],
  "lastModified": "2026-06-17T04:38:59.287",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A4FFD8B-AAFF-4187-9603-303E045ABBC6",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC5B36F0-62C9-45F9-A446-06302517C430",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1211D7C-9D7D-48D2-919E-CE69816BB5BC",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA075C4F-52CB-45DB-8FC3-9E09D748A9A7",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:meetings:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "797ADEB2-DBD7-4437-97CE-FB3AC472708D",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C49EC7B-3A03-451C-BBC4-CBD1AE555A78",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F725CBC-7382-46DB-A369-C7DE4F7BC260",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:linux:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DF05B3E-5E82-4296-A9C9-6545333C7C18",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C098940-2C55-4183-AFEC-A30423DF5EA4",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D65A2943-960F-4652-A8F3-17764952C530",
              "versionEndExcluding": "5.12.6"
            },
            {
              "criteria": "cpe:2.3:a:zoom:vdi_windows_meeting_clients:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37E75456-2466-481D-9675-6E8E1D57B147",
              "versionEndExcluding": "5.12.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@zoom.us"
}