Zoom Security Updates – 14 September 2022

Zoom has released security updates to fix vulnerabilities in Zoom On-Premise Meeting Connector (MMR) products. The remote attacker could exploit these vulnerabilities to obtain information from the affected system.

The severity of the addressed vulnerabilities could allow the remote attacker to obtain sensitive information, caused by improper access control and use this information to launch further attacks against the affected system.

Sample of The Addressed Vulnerabilities:

  1. Zoom On-Premise Meeting Connector MMR information disclosure (CVE-2022- 28758):
    • CVSS: 8.2
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Consequences: Obtain Information

  2. Zoom On-Premise Meeting Connector MMR information disclosure (CVE-2022- 28760):
    • CVSS: 6.5
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Consequences: Obtain Information
Vulnerabilities
  • CVE-2022-28758
  • CVE-2022-28759
  • CVE-2022-28760
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Zoom Security Advisor

References