Severity
High
Analysis Summary
CVE-2022-28757
Zoom Client for Meetings for macOS could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the auto update process. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges as root.
Impact
- Privilege Escalation
Indicators Of Compromise
CVE
- CVE-2022-28757
Affected Vendors
Zoom
Affected Products
Zoom Client for Meetings for macOS 5.7.3
Zoom Client for Meetings for macOS 5.11.5
Remediation
Refer to Zoom Security Advisory for patch, upgrade or suggested workaround information.