VYPR
Unrated severityNVD Advisory· Published Sep 16, 2022· Updated Sep 17, 2024

Zoom On-Premise Deployments: Improper Access Control

CVE-2022-28758

Description

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An improper access control vulnerability in Zoom On-Premise Meeting Connector MMR before 4.8.20220815.130 allows unauthorized access to meeting audio/video feeds.

Vulnerability

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability [1]. The flaw exists in the meeting management component such that a malicious actor could gain access to meeting audio and video feeds without proper authorization.

Exploitation

An attacker does not require any special authentication or privileges beyond network access to the affected Zoom On-Premise Meeting Connector MMR server [1]. By exploiting the improper access control, the attacker can intercept the audio and video streams of meetings they were not authorized to join.

Impact

Successful exploitation allows the attacker to obtain the audio and video feed of meetings they were not authorized to attend, and may also enable other meeting disruptions [1]. This leads to a compromise of confidentiality of meeting content and potential integrity/availability impacts.

Mitigation

The vulnerability is fixed in Zoom On-Premise Meeting Connector MMR version 4.8.20220815.130 [1]. Users should update to this version or later to mitigate the issue. No workarounds are mentioned in the available references.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.