Insufficient Authorization Check During Meeting Join

  • ZSB-22011
  • CVE-2022-28749
  • Medium
  • 6.5
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Zoom’s On-Premise Meeting Connector MMR before version 4.8.113.20220526 fails to properly check the permissions of a Zoom meeting attendee. As a result, a threat actor in the Zoom’s waiting room can join the meeting without the consent of the host.

 

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates from https://zoom.us/download.

  • On-Premise Meeting Connectors before version 4.8.113.20220526

Reported by Zoom Offensive Security Team

Revision Date Description
1.0 06/14/2022

Initial Publication