CVE-2022-28760: Zoom On-Premise Deployments: Improper Access Control
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28760?
CVE-2022-28760 is an improper access control vulnerability in Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130.
How does CVE-2022-28760 affect Zoom On-Premise Meeting Connector MMR?
CVE-2022-28760 could allow a malicious actor to obtain the audio and video feed of a meeting they were not authorized to join and cause disruptions.
What is the severity of CVE-2022-28760?
CVE-2022-28760 has a severity value of 6.5, classified as medium.
How can I fix CVE-2022-28760 in my Zoom On-Premise Meeting Connector MMR?
To fix CVE-2022-28760, you should update your Zoom On-Premise Meeting Connector MMR to version 4.8.20220815.130 or later.
Where can I find more information about CVE-2022-28760?
You can find more information about CVE-2022-28760 in the following security bulletin: [Zoom Security Bulletin](https://explore.zoom.us/en/trust/security/security-bulletin/)