SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-28753

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability.

MEDIUM 5.4EPSS 0.50%

Does this matter?

Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.

Description

Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access control vulnerability. As a result, a malicious actor can join a meeting which they are authorized to join without appearing to the other participants, can admit themselves into the meeting from the waiting room, and can become host and cause other meeting disruptions.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
0.50% probability · 42th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
zoom/meeting connector
Source
security@zoom.us

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.