First published: Tue Sep 13 2022(Updated: )
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
Credit: security@zoom.us
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Zoom On-premise Meeting Connector Mmr | <4.8.20220815.130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28758 is an improper access control vulnerability in Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130.
CVE-2022-28758 allows a malicious actor to obtain the audio and video feed of a meeting they were not authorized to join and cause disruptions.
CVE-2022-28758 has a severity rating of 8.2 (high).
To fix CVE-2022-28758, update Zoom On-Premise Meeting Connector MMR to version 4.8.20220815.130 or later.
You can find more information about CVE-2022-28758 at this [link](https://explore.zoom.us/en/trust/security/security-bulletin/).