CERT-In Vulnerability Note
CIVN-2022-0415
Open Redirect Vulnerability in Zoom Client for Meetings
Original Issue Date:November 01, 2022
Severity Rating: HIGH
Software Affected
- Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2
- Zoom VDI Windows Meeting Clients before version 5.12.2
- Zoom Rooms for Conference Room (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2
Overview
A vulnerability has been identified in Zoom clients for meetings, which could allow a remote attacker to redirect the user to an arbitrary network address.
Description
This vulnerability exists due to insufficient parsing of URLs. A remote attacker could exploit this vulnerability by tricking the victim into opening a specially crafted link and directing the user to connect to an arbitrary network address, leading to additional attacks, including session takeovers.
Successful exploitation of this vulnerability could allow an attacker to direct the user to connect to an arbitrary network address.
Solution
Update to the latest version as mentioned in Zooms Security advisory:
https://explore.zoom.us/en/trust/security/security-bulletin/
Vendor Information
Zoom
https://explore.zoom.us/en/trust/security/security-bulletin/
References
Zoom
https://explore.zoom.us/en/trust/security/security-bulletin/
CVE Name
CVE-2022-28763
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|