VYPR
Unrated severityNVD Advisory· Published Oct 14, 2022· Updated May 14, 2025

Zoom On-Premise Deployments: Improper Access Control

CVE-2022-28761

Description

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An improper access control vulnerability in Zoom On-Premise Meeting Connector MMR before 4.8.20220916.131 lets an authorized attacker disrupt audio/video in meetings.

Vulnerability

An improper access control vulnerability exists in Zoom On-Premise Meeting Connector MMR versions prior to 4.8.20220916.131 [1]. This flaw allows an actor who is authorized to join a meeting or webinar to disrupt audio and video delivery to other participants.

Exploitation

An attacker must be an authenticated participant in a meeting or webinar they are authorized to join [1]. No additional privileges beyond standard meeting access are required. The attacker can then trigger the vulnerability to prevent other participants from receiving audio and video streams.

Impact

Successful exploitation results in denial of service (disruption of audio and video) for other meeting or webinar participants [1]. The attacker does not gain unauthorized access to data or execute code, but causes meeting disruptions that degrade the user experience.

Mitigation

Zoom has fixed this vulnerability in version 4.8.20220916.131 of the On-Premise Meeting Connector MMR [1]. Users should update to this version or later to receive the fix. No workarounds have been published.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.