First published: Thu Aug 11 2022(Updated: )
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Meeting Connector | <4.8.129.20220714 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28754 is classified as a high severity vulnerability due to its potential for unauthorized access in Zoom meetings.
To mitigate CVE-2022-28754, update your Zoom On-Premise Meeting Connector to version 4.8.129.20220714 or later.
CVE-2022-28754 allows an attacker to join meetings without being visible to other participants, compromising meeting security.
CVE-2022-28754 affects users of Zoom On-Premise Meeting Connector versions prior to 4.8.129.20220714.
While there are no confirmed active exploits for CVE-2022-28754, its nature presents a significant risk for exploitation.