Zoom On-Prem Deployments: Improper Access Control

  • ZSB-22022
  • CVE-2022-28761
  • Medium
  • 6.5
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

For Zoom On-Premise Deployments, IT administrators can help keep their Zoom software up-to-date by following this: https://support.zoom.us/hc/en-us/articles/360043960031

  • Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131

Reported by Zoom Offensive Security Team

Revision Date Description
1.0 10/11/2022

Initial Publication