CVE-2022-28758
HIGHZoom On-Premise Meeting Connector MMR <4.8.20220815.130 - Info Disc...
Title source: llmDescription
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://explore.zoom.us/en/trust/security/security-bulletin/
Scores
CVSS v3
8.2
EPSS
0.0032
EPSS Percentile
55.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Details
CWE
CWE-284
Status
published
Products (1)
zoom/zoom_on-premise_meeting_connector_mmr
< 4.8.20220815.130
Published
Sep 16, 2022
Tracked Since
Feb 18, 2026