First published: Tue Jun 14 2022(Updated: )
Zooms On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zooms waiting room can join the meeting without the consent of the host.
Credit: security@zoom.us security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom On-Premise Meeting Connector Multimedia Router | =4.8.113.20220526 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28749 has a high severity due to the potential for unauthorized access to meetings.
To fix CVE-2022-28749, update your Zoom On-Premise Meeting Connector Multimedia Router to version 4.8.113.20220526 or later.
CVE-2022-28749 is an authorization vulnerability that allows improper permission checks for meeting attendees.
Users of Zoom On-Premise Meeting Connector Multimedia Router versions prior to 4.8.113.20220526 are affected by CVE-2022-28749.
CVE-2022-28749 could allow unauthorized users to join meetings from the waiting room without host consent.