VYPR
Unrated severityNVD Advisory· Published Oct 14, 2022· Updated May 14, 2025

Zoom On-Premise Deployments: Improper Access Control

CVE-2022-28760

Description

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Zoom On-Premise Meeting Connector MMR before 4.8.20220815.130 allows unauthorized access to meeting audio/video feeds.

Vulnerability

Zoom On-Premise Meeting Connector MMR versions before 4.8.20220815.130 contain an improper access control vulnerability. This allows an unauthorized actor to access meeting audio and video feeds and cause disruptions. The vulnerability exists in the Meeting Connector component handling meeting join requests.

Exploitation

An attacker who can reach the Zoom On-Premise Meeting Connector MMR can exploit the improper access controls to join a meeting without proper authorization. The exact steps involve sending crafted join requests that bypass authorization checks.

Impact

Successful exploitation grants an attacker unauthorized access to the audio and video feeds of meetings. The attacker can also cause other meeting disruptions, such as dropping participants or interfering with meeting controls. The impact is a breach of confidentiality and availability.

Mitigation

Zoom has released version 4.8.20220815.130 of the On-Premise Meeting Connector MMR, which fixes this vulnerability. Users should upgrade to this version or later. No workarounds are documented. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.