Update package downgrade in Zoom Client for Meetings for macOS

  • ZSB-22003
  • CVE-2022-22781
  • High
  • 7.5
  • CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

The Zoom Client for Meetings for macOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

 

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • All Zoom Client for Meetings for macOS (Standard and for IT Admin) prior to version 5.9.6

Reported by Patrick Wardle of Objective-See

Revision Date Description
1.0 04/27/2022

Initial Publication