CVE-2022-28757: Zoom Meetings

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

Affected products

  • Zoom Meetings: from 5.7.3, before 5.11.6 (fixed in 5.11.6)

Published 2022-08-18. Last modified 2026-06-17.