PT-2022-19207 · Zoom · Zoom On-Premise Meeting Connector Mmr

Published

2022-06-15

·

Updated

2023-08-08

·

CVE-2022-28749

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoom On-Premise Meeting Connector MMR version 4.8.113.20220526 and earlier
Description The issue arises from improper permission checking of Zoom meeting attendees. This allows a threat actor in the waiting room to join a meeting without the host's consent.
Recommendations For versions prior to 4.8.113.20220526, update to version 4.8.113.20220526 or later to resolve the issue.

Fix

Related Identifiers

CVE-2022-28749

Affected Products

Zoom On-Premise Meeting Connector Mmr