← Vulnerability feed

Vulnerability record · CVE-2022-22785 · published 18 May 2022

CVE-2022-22785: Zoom meetings reliance on cookies without validation vulnerability

Zoom · Meetings

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

9.1 CVSS 3.1 Critical EPSS 3.5% · top 11.4% CWE-565 · Reliance on cookies without validation
9.1CVSS 3.1 base score, v2 6.4
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies to Zoom domains. This issue could be used in a more sophisticated attack to send an unsuspecting users Zoom-scoped session cookies to a non-Zoom domain. This could potentially allow for spoofing of a Zoom user.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22785 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-34423Zoom meetings classic buffer overflow vulnerabilityA buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom C…EPSS 3.3%9.8CVE-2021-33907Zoom meetings improper certificate validation vulnerabilityThe Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files …EPSS 3.0%9.6CVE-2022-28763Zoom meetings improper input validation vulnerabilityThe Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a …EPSS 1.2%8.8CVE-2023-43582Zoom meetings improper authentication vulnerabilityImproper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.EPSS 0.66%8.8CVE-2022-22786Zoom meetings download of code without integrity check vulnerabilityThe Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properl…EPSS 1.5%8.1CVE-2022-22784Zoom meetings xml injection vulnerabilityThe Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP message…EPSS 4.0%7.8CVE-2023-28596Zoom meetings uncontrolled search path element vulnerabilityZoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could…EPSS 0.26%7.8CVE-2023-22883Zoom meetings toctou race condition vulnerabilityZoom Client for IT Admin Windows installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user cou…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2022-22785), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.