CVE Feed

    Dashboard / CVE / CVE-2022-28764

    CVE-2022-28764

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

    Published:Nov 14, 2022
    Last Modified:Apr 29, 2025
    EPS:Nov 14, 2022
    EPSS Score:0.00092
    CVSS Score:3.3

    Affected Products

    Vendor
    Zoom
    Product
    Meetings
    Vendor
    Zoom
    Product
    Rooms
    Vendor
    Zoom
    Product
    Vdi Windows Meeting Clients

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High