← Vulnerability feed

Vulnerability record · CVE-2022-28763 · published 31 October 2022

CVE-2022-28763: Zoom meetings improper input validation vulnerability

Zoom · Meetings

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.

9.6 CVSS 3.1 Critical EPSS 1.2% · top 32.8% CWE-20 · Improper input validationCWE-601 · Open redirect
9.6CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-28763 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-39213Zoom virtual desktop infrastructure injection vulnerabilityImproper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to…EPSS 1.4%9.8CVE-2021-34423Zoom meetings classic buffer overflow vulnerabilityA buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom C…EPSS 3.3%9.8CVE-2021-33907Zoom meetings improper certificate validation vulnerabilityThe Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files …EPSS 3.0%9.1CVE-2022-22785Zoom meetings reliance on cookies without validation vulnerabilityThe Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly constrain client session cookies …EPSS 3.5%8.8CVE-2023-43586Zoom meeting software development kit untrusted search path vulnerabilityPath traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct …EPSS 0.99%8.8CVE-2023-43582Zoom meetings improper authentication vulnerabilityImproper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.EPSS 0.66%8.8CVE-2023-34121Zoom rooms cross-site scripting vulnerabilityImproper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to pote…EPSS 0.95%8.8CVE-2022-22786Zoom meetings download of code without integrity check vulnerabilityThe Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properl…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2022-28763), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.