Process memory exposure in Zoom on-premise Meeting services

  • ZSB-22005
  • CVE-2022-22783
  • High
  • 8.3
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/CR:H

A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

 

Users can help keep themselves secure by applying current updates or downloading the latest Zoom software with all current security updates. 

  • Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310
  • Zoom On-Premise Meeting Connector MMR version 4.8.102.20220310

Zoom Offensive Security Team

Revision Date Description
1.0 04/27/2022

Initial Publication