Medium severity4.4NVD Advisory· Published Jan 9, 2023· Updated Jun 17, 2026
CVE-2022-36925
CVE-2022-36925
Description
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Rooms daemon service and the Zoom Rooms client was generated using parameters that could be obtained by a local low-privileged application. That key can then be used to interact with the daemon service to execute privileged functions and cause a local denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*+ 1 more
- cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:*range: <5.11.4
- (no CPE)range: <5.11.4
- Range: unspecified
Patches
Vulnerability mechanics
References
1- explore.zoom.us/en/trust/security/security-bulletin/nvdVendor Advisory
News mentions
0No linked articles in our index yet.